LIVE FEED
CRITICAL Windows KB5121767 OOB update fixes shutdowns on some Dell PCs   |   CRITICAL Critical ServiceNow code execution flaw now exploited in attacks   |   HIGH New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction   |   CRITICAL Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs   |   CRITICAL World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent   |   HIGH SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines   |   CRITICAL Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution   |   CRITICAL UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware   |   CRITICAL SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access    CRITICAL Windows KB5121767 OOB update fixes shutdowns on some Dell PCs   |   CRITICAL Critical ServiceNow code execution flaw now exploited in attacks   |   HIGH New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction   |   CRITICAL Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs   |   CRITICAL World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent   |   HIGH SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines   |   CRITICAL Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution   |   CRITICAL UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware   |   CRITICAL SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
// INTELLIGENCE FEED  1041 articles
/>
TIME:
Showing 1041 of 1041 articles
CRITICALBCJul 20, 2026#001

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]

CRITICALBCJul 20, 2026#002

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]

HIGHTHNJul 20, 2026#003

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Ini...

CRITICALTHNJul 20, 2026#004

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an...

INFOMSRCJul 20, 2026#005

CVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoS

Information published.

MEDIUMMSRCJul 20, 2026#006

CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

Information published.

INFOMSRCJul 20, 2026#007

CVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry()

Information published.

INFOMSRCJul 20, 2026#008

CVE-2026-53381 virtiofs: fix UAF on submount umount

Information published.

INFOMSRCJul 20, 2026#009

CVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error path

Information published.

INFOMSRCJul 20, 2026#010

CVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si

Information published.

INFOMSRCJul 20, 2026#011

CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg

Information published.

INFOMSRCJul 20, 2026#012

CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done

Information published.

INFOMSRCJul 20, 2026#013

CVE-2026-63812 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()

Information published.

INFOMSRCJul 20, 2026#014

CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors

Information published.

INFOMSRCJul 20, 2026#015

CVE-2026-63836 batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd

Information published.

INFOMSRCJul 20, 2026#016

CVE-2026-53397 nfsd: fix posix_acl leak on SETACL decode failure

Information published.

MEDIUMMSRCJul 20, 2026#017

CVE-2026-63822 wifi: ath11k: fix warning when unbinding

Information published.

INFOMSRCJul 20, 2026#018

CVE-2026-53391 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr

Information published.

INFOMSRCJul 20, 2026#019

CVE-2026-63834 batman-adv: tp_meter: restrict number of unacked list entries

Information published.

INFOMSRCJul 20, 2026#020

CVE-2026-63803 hdlc_ppp: sync per-proto timers before freeing hdlc state

Information published.

INFOMSRCJul 20, 2026#021

CVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardif

Information published.

INFOMSRCJul 20, 2026#022

CVE-2026-63809 bpf: use kvfree() for replaced sysctl write buffer

Information published.

INFOMSRCJul 20, 2026#023

CVE-2026-53393 nfsd: reset write verifier on deferred writeback errors

Information published.

INFOMSRCJul 20, 2026#024

CVE-2026-53387 iio: light: veml6075: add bounds check to veml6075_it_ms index

Information published.

INFOMSRCJul 20, 2026#025

CVE-2026-63832 wifi: mt76: add wcid publish check in mt76_sta_add

Information published.

MEDIUMMSRCJul 20, 2026#026

CVE-2026-53375 drm/amdgpu/vce: Prevent partial address patches

Information published.

INFOMSRCJul 20, 2026#027

CVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink

Information published.

INFOMSRCJul 20, 2026#028

CVE-2026-63818 f2fs: validate orphan inode entry count

Information published.

INFOMSRCJul 20, 2026#029

CVE-2026-63858 netfilter: nf_tables: add hook transactions for device deletions

Information published.

INFOMSRCJul 20, 2026#030

CVE-2026-63826 fbdev: fix use-after-free in store_modes()

Information published.

INFOMSRCJul 20, 2026#031

CVE-2026-53399 nfsd: release layout stid on setlease failure

Information published.

INFOMSRCJul 20, 2026#032

CVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failure

Information published.

INFOMSRCJul 20, 2026#033

CVE-2026-63871 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls

Information published.

INFOMSRCJul 20, 2026#034

CVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrs

Information published.

INFOMSRCJul 20, 2026#035

CVE-2026-53400 i2c: core: fix adapter registration race

Information published.

INFOMSRCJul 20, 2026#036

CVE-2026-53368 f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage

Information published.

INFOMSRCJul 20, 2026#037

CVE-2026-53377 drm/msm: always recover the gpu

Information published.

INFOMSRCJul 20, 2026#038

CVE-2026-63806 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()

Information published.

INFOMSRCJul 20, 2026#039

CVE-2026-53376 drm/amdkfd: Add upper bound check for num_of_nodes

Information published.

INFOMSRCJul 20, 2026#040

CVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var

Information published.

INFOMSRCJul 20, 2026#041

CVE-2026-63793 ntfs: serialize volume label accesses

Information published.

INFOMSRCJul 20, 2026#042

CVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocation

Information published.

INFOMSRCJul 20, 2026#043

CVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version count

Information published.

INFOMSRCJul 20, 2026#044

CVE-2026-63811 f2fs: read COW data with the original inode during atomic write

Information published.

INFOMSRCJul 20, 2026#045

CVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmap

Information published.

INFOMSRCJul 20, 2026#046

CVE-2026-63810 block: Avoid mounting the bdev pseudo-filesystem in userspace

Information published.

INFOMSRCJul 20, 2026#047

CVE-2026-63819 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()

Information published.

INFOMSRCJul 20, 2026#048

CVE-2026-53402 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()

Information published.

INFOMSRCJul 20, 2026#049

CVE-2026-63853 drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring

Information published.

INFOMSRCJul 20, 2026#050

CVE-2026-53386 iio: adc: ti-ads1298: add bounds check to pga_settings index

Information published.

MEDIUMMSRCJul 20, 2026#051

CVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashes

Information published.

INFOMSRCJul 20, 2026#052

CVE-2026-63816 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode

Information published.

INFOMSRCJul 20, 2026#053

CVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argument

Information published.

INFOMSRCJul 20, 2026#054

CVE-2026-63815 f2fs: bound i_inline_xattr_size for non-inline-xattr inodes

Information published.

CRITICALTHNJul 20, 2026#055

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to th...

HIGHTHNJul 20, 2026#056

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional pa...

CRITICALTHNJul 19, 2026#057

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx ...

MEDIUMBCJul 19, 2026#058

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]

CRITICALTHNJul 19, 2026#059

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emerg...

CRITICALTHNJul 19, 2026#060

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 2...

CRITICALBCJul 18, 2026#061

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

CRITICALBCJul 18, 2026#062

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]

HIGHBCJul 18, 2026#063

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]

INFOBCJul 18, 2026#064

The Future of Age Verification: Your Face Never Leaves Your Device

As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitti...

INFOMSRCJul 18, 2026#065

CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling

Information published.

MEDIUMMSRCJul 18, 2026#066

CVE-2026-47729 Squid: Memory disclosure in FTP gateway

Information published.

INFOMSRCJul 18, 2026#067

CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record

Information published.

INFOMSRCJul 18, 2026#068

CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS

Information published.

HIGHMSRCJul 18, 2026#069

Chromium: CVE-2026-15905 Use after free in Aura

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#070

Chromium: CVE-2026-15904 Use after free in Ozone

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#071

Chromium: CVE-2026-15903 Out of bounds read and write in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#072

Chromium: CVE-2026-15902 Use after free in Cast

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#073

Chromium: CVE-2026-15901 Use after free in Network

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#074

Chromium: CVE-2026-15900 Use after free in GPU

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 18, 2026#075

Chromium: CVE-2026-15899 Use after free in CameraCapture

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHTHNJul 17, 2026#076

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of i...

HIGHBCJul 17, 2026#077

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a sepa...

MEDIUMTHNJul 17, 2026#078

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the...

CRITICALDRJul 17, 2026#079

Inc Ransomware Exploits SonicWall SMA Zero-Days

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.

HIGHTHNJul 17, 2026#080

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed Vite...

HIGHBCJul 17, 2026#081

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]

INFOTHNJul 17, 2026#082

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, O...

CRITICALDRJul 17, 2026#083

The Real AI Threat Is Blind Trust

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.

HIGHTHNJul 17, 2026#084

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor a...

HIGHBCJul 17, 2026#085

Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]

INFOBCJul 17, 2026#086

Inside the Search for "Clean" Residential Proxies for Carding

Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles,...

CRITICALMSRCJul 17, 2026#087

CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability

Added acknowledgements. This is an informational change only.

HIGHTHNJul 17, 2026#088

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding ...

HIGHDRJul 17, 2026#089

Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear

The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.

HIGHDRJul 17, 2026#090

Google Bets 'Agentic Defense' Strategy Can Outpace Attackers

Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.

INFOTHNJul 17, 2026#091

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the displ...

CRITICALTHNJul 17, 2026#092

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are...

CRITICALBCJul 17, 2026#093

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. [...]

CRITICALTHNJul 17, 2026#094

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV t...

MEDIUMBCJul 17, 2026#095

Windows Server 2022 reach end of mainstream support in 90 days

Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. [...]

INFOTHNJul 17, 2026#096

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint...

HIGHTHNJul 17, 2026#097

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access...

INFOBCJul 17, 2026#098

US charges two over laundering $43 million from investment fraud

U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...]

CRITICALMSRCJul 17, 2026#099

CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values

Information published.

INFOMSRCJul 17, 2026#100

CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

Information published.

INFOMSRCJul 17, 2026#101

CVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service

Information published.

INFOMSRCJul 17, 2026#102

CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index

Information published.

INFOMSRCJul 17, 2026#103

CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location

Information published.

CRITICALMSRCJul 17, 2026#104

CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row

Information published.

INFOMSRCJul 17, 2026#105

CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on text

Information published.

INFOMSRCJul 17, 2026#106

CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record

Information published.

INFOMSRCJul 17, 2026#107

CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service

Information published.

INFOMSRCJul 17, 2026#108

CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption

Information published.

INFOMSRCJul 17, 2026#109

CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string

Information published.

INFOMSRCJul 17, 2026#110

CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak

Information published.

INFOMSRCJul 17, 2026#111

CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation

Information published.

INFOMSRCJul 17, 2026#112

CVE-2026-53366 ipv4: account for fraggap on the paged allocation path

Information published.

INFOMSRCJul 17, 2026#113

CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service

Information published.

CRITICALBCJul 17, 2026#114

CISA urges immediate action on actively exploited Fortinet flaws

CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. [...]

CRITICALTHNJul 17, 2026#115

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Feder...

CRITICALBCJul 16, 2026#116

New ClickLock macOS malware traps users into revealing login password

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]

CRITICALBCJul 16, 2026#117

Coca-Cola says Fairlife ransomware attack halts US dairy production

The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]

HIGHDRJul 16, 2026#118

Agentic AI Is Untamable: Ask the Right Security Questions

Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.

HIGHDRJul 16, 2026#119

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.

CRITICALBCJul 16, 2026#120

Claude Chrome extension flaw lets malicious extensions trigger AI actions

A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected servic...

HIGHBCJul 16, 2026#121

New OkoBot framework deploys 20 payloads to steal data, crypto

A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. [...]

CRITICALTHNJul 16, 2026#122

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inopera...

CRITICALTHNJul 16, 2026#123

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage...

INFOBCJul 16, 2026#124

AI Agents Broke the Security Playbook. Here's What Replaces It.

Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the...

CRITICALMSRCJul 16, 2026#125

CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 16, 2026#126

CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#127

CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#128

CVE-2026-58643 Windows Admin Center Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

CRITICALMSRCJul 16, 2026#129

CVE-2026-58598 Windows Backup Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 16, 2026#130

CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#131

CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#132

CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#133

CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#134

CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#135

CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability

Updated product information in the Software Update table. This is an informational change only.

HIGHMSRCJul 16, 2026#136

CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

HIGHBCJul 16, 2026#137

23andMe to pay $18 million in new genetics data breach settlement

Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]

HIGHTHNJul 16, 2026#138

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub&n...

HIGHTHNJul 16, 2026#139

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, ...

INFOTHNJul 16, 2026#140

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a...

INFOBCJul 16, 2026#141

Scattered Spider members behind TfL hack get five years in prison

Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]

MEDIUMBCJul 16, 2026#142

Windows 11 24H2 Home and Pro reach end of support in 90 days

Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. [...]

HIGHTHNJul 16, 2026#143

20+ Hijacked Government Websites Became
an Attack Channel

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat i...

HIGHTHNJul 16, 2026#144

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can...

HIGHTHNJul 16, 2026#145

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("s...

CRITICALBCJul 16, 2026#146

CISA orders feds to patch actively exploited Oracle flaw by Saturday

CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...]

HIGHBCJul 16, 2026#147

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...]

HIGHTHNJul 16, 2026#148

AI Can Find Bugs, But Human Knowledge Still Proves Them

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate p...

CRITICALBCJul 16, 2026#149

New Spirals ransomware encrypts victim network in under 24 hours

A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. [...]

HIGHTHNJul 16, 2026#150

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the hous...

HIGHTHNJul 16, 2026#151

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong ...

CRITICALTHNJul 16, 2026#152

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom D...

HIGHDRJul 16, 2026#153

Police Disrupt a €140M Cyber Fraud Ring in Spain

Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.

INFOBCJul 15, 2026#154

Dutch police bust investment fraud ring stealing over €100 million

The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]

HIGHDRJul 15, 2026#155

Forgotten Bootloaders Expose Secure Boot Blind Spot

Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.

CRITICALDRJul 15, 2026#156

Identity Attacks Overtake Exploits as Top Ransomware Cause

Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

CRITICALBCJul 15, 2026#157

Zoom warns of critical account takeover vulnerability

Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]

INFOTHNJul 15, 2026#158

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language m...

CRITICALBCJul 15, 2026#159

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]

CRITICALDRJul 15, 2026#160

Guten Tag, Bonjour, Hola to Our European Cyber Defenders!

We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.

INFODRJul 15, 2026#161

Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife

The US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.

HIGHBCJul 15, 2026#162

AsyncAPI npm packages infected with credential-stealing malware

Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. [...]

HIGHTHNJul 15, 2026#163

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes f...

HIGHDRJul 15, 2026#164

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

When combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.

CRITICALBCJul 15, 2026#165

We built a vulnerability vending machine: AI tokens in, zero-days out

Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a prev...

CRITICALMSRCJul 15, 2026#166

CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability

Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only.

HIGHMSRCJul 15, 2026#167

CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability

Updated acknowledgment. This is an informational change only.

HIGHMSRCJul 15, 2026#168

CVE-2026-50375 DirectX Graphics Kernel Elevation of Privilege Vulnerability

Updated acknowledgment. This is an informational change only.

HIGHMSRCJul 15, 2026#169

CVE-2026-56182 Windows NTFS Elevation of Privilege Vulnerability

Updated acknowledgment. This is an informational change only.

CRITICALTHNJul 15, 2026#170

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaSc...

CRITICALDRJul 15, 2026#171

2-Click Cursor Exploit Enables Dev Environment Takeover

Simple age-old bugs give bad actors access to developers' secrets and source code-rich environments.

INFOTHNJul 15, 2026#172

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applicati...

CRITICALTHNJul 15, 2026#173

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of p...

HIGHTHNJul 15, 2026#174

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approv...

CRITICALTHNJul 15, 2026#175

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute....

CRITICALBCJul 15, 2026#176

CISA warns admins to patch actively exploited SharePoint flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]

HIGHTHNJul 15, 2026#177

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are ...

INFOMSRCJul 15, 2026#178

CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2

Information published.

INFOMSRCJul 15, 2026#179

CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI

Information published.

INFOMSRCJul 15, 2026#180

CVE-2025-44904 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.

Information published.

MEDIUMBCJul 15, 2026#181

Microsoft: Some Dell PCs shut down after recent Windows updates

Microsoft is blocking this month's Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues. [...]

INFOMSRCJul 15, 2026#182

CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom

Information published.

INFOMSRCJul 15, 2026#183

CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows

Information published.

CRITICALMSRCJul 15, 2026#184

CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks

Information published.

INFOMSRCJul 15, 2026#185

CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering

Information published.

INFOMSRCJul 15, 2026#186

CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

Information published.

CRITICALMSRCJul 15, 2026#187

CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS

Information published.

MEDIUMMSRCJul 15, 2026#188

CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations

Information published.

CRITICALMSRCJul 15, 2026#189

CVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace

Information published.

INFOMSRCJul 15, 2026#190

CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header

Information published.

INFOMSRCJul 15, 2026#191

CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Information published.

INFOMSRCJul 15, 2026#192

CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls

Information published.

INFOMSRCJul 15, 2026#193

CVE-2026-39822 Root escape via symlink plus trailing slash in os

Information published.

INFOMSRCJul 15, 2026#194

CVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk

Information published.

INFOMSRCJul 15, 2026#195

CVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack

Information published.

CRITICALDRJul 15, 2026#196

Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.

CRITICALBCJul 15, 2026#197

US charges alleged operators of Russian bulletproof hosting service

U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwi...

CRITICALTHNJul 15, 2026#198

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulner...

INFODRJul 15, 2026#199

Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal

CardinalOps will give Cribl customers the ability to map detection rules and security controls to the MITRE ATT&CK framework. SecOps teams can identify coverage gaps and operationalize threat intelligence.

CRITICALDRJul 14, 2026#200

Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes

Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.

CRITICALBCJul 14, 2026#201

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...

CRITICALTHNJul 14, 2026#202

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide c...

HIGHBCJul 14, 2026#203

Spanish Police take down €140 million cyber fraud ring, arrest four

The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]

CRITICALDRJul 14, 2026#204

6 GHz Wi-Fi Flaws Could Disrupt Critical Systems

Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.

HIGHKREBSJul 14, 2026#205

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-...

HIGHBCJul 14, 2026#206

Nearly 300 GitHub repos pose as legit software to push malware

A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]

MEDIUMBCJul 14, 2026#207

Microsoft releases Windows 10 KB5099539 extended security update

Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. [...]

CRITICALTHNJul 14, 2026#208

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-447...

CRITICALBCJul 14, 2026#209

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...]

INFODRJul 14, 2026#210

Manage Vendor Risk in a Few Practical Steps

Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.

MEDIUMBCJul 14, 2026#211

Windows 11 KB5101650 & KB5099414 cumulative updates released

Microsoft has released Windows 11's June 2026 Update for version 25H2, 24H2, and 23H2, bringing fixes for over 570 security issues. [...]

INFOTHNJul 14, 2026#212

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a ...

HIGHTHNJul 14, 2026#213

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reus...

CRITICALBCJul 14, 2026#214

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...]

INFODRJul 14, 2026#215

Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?

Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.

HIGHDRJul 14, 2026#216

ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.

HIGHBCJul 14, 2026#217

LastPass, Bitwarden users targeted with fake security alerts

LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]

CRITICALBCJul 14, 2026#218

You Don't Have to Run an Exploit to Know If You're Vulnerable

Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploit...

CRITICALMSRCJul 14, 2026#219

CVE-2026-48561 Microsoft Copilot Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 14, 2026#220

CVE-2026-42982 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#221

CVE-2026-47296 Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#222

CVE-2026-34349 Windows Media Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

HIGHMSRCJul 14, 2026#223

CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CRITICALMSRCJul 14, 2026#224

CVE-2026-42900 Microsoft Windows App Store Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

CRITICALMSRCJul 14, 2026#225

CVE-2026-42975 Windows Bluetooth Port Driver Remote Code Execution

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

HIGHMSRCJul 14, 2026#226

CVE-2026-47300 ASP.NET Core Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

CRITICALMSRCJul 14, 2026#227

CVE-2026-47302 .NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

HIGHMSRCJul 14, 2026#228

CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

HIGHMSRCJul 14, 2026#229

CVE-2026-42990 SQL Server ODBC driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 14, 2026#230

CVE-2026-48572 Windows App Package Installer Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#231

CVE-2026-48571 Windows App Package Installer Elevation of Privilege Vulnerability

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#232

CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CRITICALMSRCJul 14, 2026#233

CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 14, 2026#234

CVE-2026-49165 Microsoft Windows App Store Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

HIGHMSRCJul 14, 2026#235

CVE-2026-49166 Windows Print Configuration Elevation of Privilege Vulnerability

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#236

CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#237

CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

CRITICALMSRCJul 14, 2026#238

CVE-2026-49169 Windows DNS Server Remote Code Execution Vulnerability

Use after free in DNS Server allows an authorized attacker to execute code over a network.

HIGHMSRCJul 14, 2026#239

CVE-2026-49170 Windows StateRepository API Server file Elevation of Privilege Vulnerability

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#240

CVE-2026-49171 Windows Speech Runtime Elevation of Privilege Vulnerability

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

HIGHMSRCJul 14, 2026#241

CVE-2026-49176 Windows WalletService Elevation of Privilege Vulnerability

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

HIGHTHNJul 14, 2026#242

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infr...

HIGHDRJul 14, 2026#243

Cursor IDE Auto-Executes Malicious Code in Poisoned Repos

Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.

INFOBCJul 14, 2026#244

Microsoft Entra ID gets passkeys default authentication starting September

Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]

HIGHBCJul 14, 2026#245

New phishing kits target Microsoft 365 accounts, evade MFA

Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]

HIGHTHNJul 14, 2026#246

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard....

INFOTHNJul 14, 2026#247

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk ...

CRITICALBCJul 14, 2026#248

SAP warns of critical flaws in NetWeaver and Commerce Cloud

SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]

HIGHTHNJul 14, 2026#249

How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: sca...

HIGHTHNJul 14, 2026#250

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and v...

INFOBCJul 14, 2026#251

Microsoft starts testing cleaner Windows Search without ads

Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]

CRITICALTHNJul 14, 2026#252

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, ...

CRITICALTHNJul 14, 2026#253

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including r...

INFOMSRCJul 14, 2026#254

CVE-2026-40467 Use after free in gawk

Information published.

INFOMSRCJul 14, 2026#255

CVE-2026-40468 Heap buffer overflow in gawk

Information published.

INFOMSRCJul 14, 2026#256

CVE-2026-40469 Heap buffer overflow in gawk

Information published.

INFOMSRCJul 14, 2026#257

CVE-2026-40553 Stack-based buffer overflow in gawk

Information published.

INFOTHNJul 14, 2026#258

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages...

CRITICALTHNJul 14, 2026#259

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in h...

HIGHDRJul 13, 2026#260

Weak Security Continues to Fuel Russian Cyberattacks

In a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.

HIGHBCJul 13, 2026#261

Japan's largest taxi operator shuts systems after cyberattack

Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]

HIGHBCJul 13, 2026#262

Hackers backdoor Jscrambler npm package with infostealer malware

The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]

HIGHBCJul 13, 2026#263

New CrashStealer malware poses as Apple crash reporting tool

A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]

HIGHDRJul 13, 2026#264

'Yellow Teams' Are Defining the Future of AI Security

In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.

HIGHTHNJul 13, 2026#265

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleS...

INFOTHNJul 13, 2026#266

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official...

HIGHDRJul 13, 2026#267

GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.

CRITICALBCJul 13, 2026#268

CISA warns of actively exploited RCE flaws in Joomla extensions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through a...

CRITICALTHNJul 13, 2026#269

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they d...

INFOKREBSJul 13, 2026#270

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub ...

HIGHBCJul 13, 2026#271

Lidl discloses online shop breach after service provider hack

German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]

HIGHBCJul 13, 2026#272

Breach at the Beach: Play the Ultimate Entra ID CTF

Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]

HIGHTHNJul 13, 2026#273

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the...

INFOBCJul 13, 2026#274

UK charges suspects linked to Russian Coms call spoofing platform

UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls. [...]

HIGHTHNJul 13, 2026#275

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, a...

CRITICALDRJul 13, 2026#276

Turning the Tables on Email Scammers With 'ScamBuster'

An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.

INFOTHNJul 13, 2026#277

Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinn...

INFOTHNJul 13, 2026#278

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few ...

HIGHBCJul 13, 2026#279

EU sanctions Russian GRU military hackers over cyberattacks

The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]

HIGHTHNJul 13, 2026#280

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and ...

CRITICALBCJul 13, 2026#281

US and allies warn of Russian critical infrastructure attacks

Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure ...

INFOMSRCJul 13, 2026#282

CVE-2025-38096 wifi: iwlwifi: don't warn when if there is a FW error

Information published.

HIGHMSRCJul 13, 2026#283

CVE-2022-4543 A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

Information published.

HIGHTHNJul 13, 2026#284

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sit...

CRITICALTHNJul 13, 2026#285

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, fo...

INFOBCJul 13, 2026#286

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]

INFOBCJul 12, 2026#287

Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time

Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]

HIGHBCJul 12, 2026#288

RedHook Android malware now uses Wireless ADB for shell access

A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. [...]

HIGHMSRCJul 12, 2026#289

CVE-2026-45489 Microsoft Edge (Chromium-based) Spoofing Vulnerability

CWE added. Informational change only.

INFOMSRCJul 12, 2026#290

CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace

Information published.

INFOMSRCJul 12, 2026#291

CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input

Information published.

INFOMSRCJul 12, 2026#292

CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion

Information published.

INFOMSRCJul 12, 2026#293

CVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Information published.

HIGHMSRCJul 11, 2026#294

Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#295

Chromium: CVE-2026-13788 Use after free in Fullscreen

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#296

Chromium: CVE-2026-13807 Use after free in Import

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

CRITICALMSRCJul 11, 2026#297

Chromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOS

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#298

Chromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWeb

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#299

Chromium: CVE-2026-14424 Use after free in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#300

Chromium: CVE-2026-14422 Out of bounds read and write in Tint

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#301

Chromium: CVE-2026-14397 Out of bounds write in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#302

Chromium: CVE-2026-14396 Out of bounds read in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#303

Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloads

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#304

Chromium: CVE-2026-13785 Use after free in Bluetooth

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#305

Chromium: CVE-2026-13778 Use after free in WebUSB

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#306

Chromium: CVE-2026-14421 Uninitialized Use in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#307

Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#308

Chromium: CVE-2026-14432 Use after free in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#309

Chromium: CVE-2026-14431 Type Confusion in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#310

Chromium: CVE-2026-14430 Integer overflow in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#311

Chromium: CVE-2026-14429 Insufficient validation of untrusted input in Skia

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#312

Chromium: CVE-2026-14427 Heap buffer overflow in Skia

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#313

Chromium: CVE-2026-14426 Use after free in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#314

Chromium: CVE-2026-14425 Use after free in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#315

Chromium: CVE-2026-14423 Type Confusion in Tint

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#316

Chromium: CVE-2026-14420 Out of bounds read and write in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#317

Chromium: CVE-2026-14419 Use after free in Skia

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#318

Chromium: CVE-2026-14418 Uninitialized Use in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#319

Chromium: CVE-2026-14417 Use after free in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#320

Chromium: CVE-2026-14416 Out of bounds read in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#321

Chromium: CVE-2026-14415 Inappropriate implementation in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#322

Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#323

Chromium: CVE-2026-14413 Uninitialized Use in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#324

Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#325

Chromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#326

Chromium: CVE-2026-14410 Inappropriate implementation in Skia

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#327

Chromium: CVE-2026-14409 Inappropriate implementation in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#328

Chromium: CVE-2026-14408 Uninitialized Use in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#329

Chromium: CVE-2026-14407 Inappropriate implementation in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#330

Chromium: CVE-2026-14406 Out of bounds read in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#331

Chromium: CVE-2026-14405 Uninitialized Use in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#332

Chromium: CVE-2026-14404 Inappropriate implementation in PDFium

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#333

Chromium: CVE-2026-14403 Use after free in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#334

Chromium: CVE-2026-14402 Uninitialized Use in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#335

Chromium: CVE-2026-14400 Out of bounds write in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#336

Chromium: CVE-2026-14399 Uninitialized Use in Dawn

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#337

Chromium: CVE-2026-14398 Use after free in ANGLE

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#338

Chromium: CVE-2026-14395 Out of bounds write in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJul 11, 2026#339

Chromium: CVE-2026-14394 Use after free in V8

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

INFOTHNJul 11, 2026#340

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook th...

CRITICALTHNJul 11, 2026#341

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between Februa...

HIGHBCJul 11, 2026#342

Australia warns of global campaign targeting vulnerable CMS platforms

The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]

INFOBCJul 11, 2026#343

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, th...

INFOMSRCJul 11, 2026#344

CVE-2026-45570 go-git: Improper single-quote escaping in go-git SSH transport

Information published.

INFOMSRCJul 11, 2026#345

CVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directories

Information published.

INFOMSRCJul 11, 2026#346

CVE-2024-7598 Network restriction bypass via race condition during namespace termination

Information published.

INFOMSRCJul 11, 2026#347

CVE-2026-58253 NATS Server: Route API Auth Bypass

Information published.

INFOMSRCJul 11, 2026#348

CVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filters

Information published.

INFOMSRCJul 11, 2026#349

CVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-Overlap

Information published.

INFOMSRCJul 11, 2026#350

CVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshake

Information published.

INFOMSRCJul 11, 2026#351

CVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled

Information published.

INFOMSRCJul 11, 2026#352

CVE-2026-58251 NATS Server: Queue Subscribe Authz Bypass

Information published.

INFOMSRCJul 11, 2026#353

CVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz pagination

Information published.

CRITICALMSRCJul 11, 2026#354

CVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumption

Information published.

INFOMSRCJul 11, 2026#355

CVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

Information published.

HIGHMSRCJul 11, 2026#356

CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content

Information published.

INFOMSRCJul 11, 2026#357

CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)

Information published.

INFOMSRCJul 11, 2026#358

CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

Information published.

INFOMSRCJul 11, 2026#359

CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive

Information published.

INFOMSRCJul 11, 2026#360

CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

Information published.

INFOMSRCJul 11, 2026#361

CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment

Information published.

INFOMSRCJul 11, 2026#362

CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile

Information published.

INFOMSRCJul 11, 2026#363

CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders

Information published.

INFOMSRCJul 11, 2026#364

CVE-2026-14461 Out-of-bound read in mtr

Information published.

INFOMSRCJul 11, 2026#365

CVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Information published.

HIGHMSRCJul 11, 2026#366

CVE-2026-20244 ClamAV DMG File Processing Denial of Service Vulnerability

Information published.

HIGHMSRCJul 11, 2026#367

CVE-2026-20243 ClamAV ALZ Archive Processing Denial of Service Vulnerability

Information published.

HIGHMSRCJul 11, 2026#368

CVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability

Information published.

CRITICALMSRCJul 11, 2026#369

CVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability

Information published.

HIGHMSRCJul 11, 2026#370

CVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability

Information published.

HIGHMSRCJul 11, 2026#371

CVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability

Information published.

HIGHMSRCJul 11, 2026#372

CVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability

Information published.

INFOMSRCJul 11, 2026#373

CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion

Information published.

CRITICALTHNJul 11, 2026#374

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of ...

HIGHBCJul 10, 2026#375

New U-Boot flaws could enable stealthy firmware attacks

Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise securi...

INFODRJul 10, 2026#376

Jen Ellis: Connecting Cyber Community With Political Machinery

Security Pro File: On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Jen Ellis' advocacy on behalf of security researchers.

CRITICALBCJul 10, 2026#377

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]

HIGHDRJul 10, 2026#378

Cybercriminals Flock to Healthcare Businesses as Attacks Surge

While cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.

HIGHBCJul 10, 2026#379

Police suspects Dutch hackers were involved in Odido breach

The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]

INFOTHNJul 10, 2026#380

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The c...

INFOTHNJul 10, 2026#381

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phras...

INFOBCJul 10, 2026#382

Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-prem...

HIGHTHNJul 10, 2026#383

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center ...

CRITICALBCJul 10, 2026#384

Hackers exploit critical auth bypass in Gitea Docker image

Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]

INFOBCJul 10, 2026#385

Money launderer accused of stealing seized crypto while in prison

A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]

CRITICALTHNJul 10, 2026#386

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. N...

HIGHTHNJul 10, 2026#387

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitr...

HIGHBCJul 10, 2026#388

The Replicant in Your Directory: AI Agents and the Identity Security Gap

AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity gove...

INFODRJul 10, 2026#389

Fresh ATM Crypto Software Bugs: Jackpot or Bust?

Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.

INFODRJul 10, 2026#390

More Countries Jump on the Social Media 'Ban Wagon'

Age restrictions on accounts may be more of a stopgap because industry compliance is already falling short. Tech giants are struggling to follow the laws without affecting users.

HIGHTHNJul 10, 2026#391

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may app...

INFODRJul 10, 2026#392

AI Coding: Do Security Risks Outweigh Productivity Gains?

AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?

MEDIUMTHNJul 10, 2026#393

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry...

CRITICALBCJul 10, 2026#394

Zimbra urges customers to patch critical web client XSS flaw

The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]

INFOTHNJul 10, 2026#395

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organiz...

HIGHTHNJul 10, 2026#396

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million ...

INFOTHNJul 10, 2026#397

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure....

HIGHTHNJul 10, 2026#398

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion atta...

HIGHTHNJul 10, 2026#399

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that cont...

CRITICALBCJul 10, 2026#400

Former ransomware negotiator gets 4 years for BlackCat attacks

A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]

CRITICALTHNJul 10, 2026#401

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple...

MEDIUMMSRCJul 10, 2026#402

CVE-2026-56288 NULL Pointer Dereference in GNU patch

Information published.

MEDIUMMSRCJul 10, 2026#403

CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch

Information published.

CRITICALMSRCJul 10, 2026#404

CVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation

Information published.

INFOBCJul 09, 2026#405

OpenMandriva Linux says contributor tried to sabotage the project

The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]

CRITICALDRJul 09, 2026#406

Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure

Obscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.

CRITICALDRJul 09, 2026#407

Microsoft Reins in RoguePlanet Zero-Day Threat

The researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.

INFOBCJul 09, 2026#408

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases....

INFODRJul 09, 2026#409

AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready

If you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.

HIGHTHNJul 09, 2026#410

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on aut...

CRITICALTHNJul 09, 2026#411

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can cho...

HIGHBCJul 09, 2026#412

New Helix vishing group emerges in SharePoint data theft attacks

A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [....

MEDIUMBCJul 09, 2026#413

Microsoft expects more Windows security updates from AI-discovered flaws

Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]

INFOTHNJul 09, 2026#414

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Micros...

INFOTHNJul 09, 2026#415

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not lo...

HIGHBCJul 09, 2026#416

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. [...]

INFODRJul 09, 2026#417

As Global Conflicts Go Digital, Businesses Need Wartime Gameplans

The fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves.

INFOBCJul 09, 2026#418

The Hidden Security Risks of Reduced Summer IT Coverage

Security operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance o...

HIGHDRJul 09, 2026#419

AI Gateways Offer Attackers the Keys to the Kingdom

A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.

HIGHTHNJul 09, 2026#420

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your ...

MEDIUMBCJul 09, 2026#421

Microsoft to retire the OWA Light client in Exchange Server

Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]

INFOTHNJul 09, 2026#422

Summer of Clearinghouses

Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quie...

CRITICALTHNJul 09, 2026#423

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report pub...

CRITICALDRJul 09, 2026#424

'GodDamn' Ransomware Uses BYOVD to Smite US Companies

Microsoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.

CRITICALBCJul 09, 2026#425

Police arrests 5,800 suspects in global anti-fraud crackdown

Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]

INFOMSRCJul 09, 2026#426

CVE-2026-53359 KVM: x86: Fix shadow paging use-after-free due to unexpected role

Information published.

INFOMSRCJul 09, 2026#427

CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

Information published.

INFOMSRCJul 09, 2026#428

CVE-2026-8925 SASL double-free

Information published.

INFOMSRCJul 09, 2026#429

CVE-2026-8927 env-set cross-proxy Digest auth state leak

Information published.

HIGHTHNJul 09, 2026#430

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a pri...

INFOMSRCJul 09, 2026#431

CVE-2026-12064 proto-default skips SSH verification

Information published.

INFOMSRCJul 09, 2026#432

CVE-2026-46242 eventpoll: fix ep_remove struct eventpoll / struct file UAF

Information published.

INFOMSRCJul 09, 2026#433

CVE-2026-46135 nvmet-tcp: fix race between ICReq handling and queue teardown

Information published.

INFOMSRCJul 09, 2026#434

CVE-2026-11856 cross-origin Digest auth state leak

Information published.

INFOMSRCJul 09, 2026#435

CVE-2026-46054 selinux: fix overlayfs mmap() and mprotect() access checks

Information published.

INFOMSRCJul 09, 2026#436

CVE-2026-9547 SSH improper host validation

Information published.

INFOMSRCJul 09, 2026#437

CVE-2026-9079 stale proxy password leak

Information published.

INFOMSRCJul 09, 2026#438

CVE-2026-53339 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()

Information published.

INFOMSRCJul 09, 2026#439

CVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown types

Information published.

INFOMSRCJul 09, 2026#440

CVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_on

Information published.

INFOMSRCJul 09, 2026#441

CVE-2026-53332 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd

Information published.

INFOMSRCJul 09, 2026#442

CVE-2026-43010 bpf: Reject sleepable kprobe_multi programs at attach time

Information published.

INFOMSRCJul 09, 2026#443

CVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying

Information published.

INFOMSRCJul 09, 2026#444

CVE-2026-53354 arm64: errata: Mitigate TLBI errata on various Arm CPUs

Information published.

INFOMSRCJul 09, 2026#445

CVE-2026-23278 netfilter: nf_tables: always walk all pending catchall elements

Information published.

INFOMSRCJul 09, 2026#446

CVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x509

Information published.

INFOMSRCJul 09, 2026#447

CVE-2025-61724 Excessive CPU consumption in Reader.ReadResponse in net/textproto

Information published.

INFOMSRCJul 09, 2026#448

CVE-2025-23131 dlm: prevent NPD when writing a positive value to event_done

Information published.

INFOMSRCJul 09, 2026#449

CVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Information published.

INFOMSRCJul 09, 2026#450

CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.

Information published.

HIGHMSRCJul 09, 2026#451

CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

Information published.

INFOMSRCJul 09, 2026#452

CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader

Information published.

INFOMSRCJul 09, 2026#453

CVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()

Information published.

INFOMSRCJul 09, 2026#454

CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow

Information published.

INFOMSRCJul 09, 2026#455

CVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer Overflow

Information published.

INFOMSRCJul 09, 2026#456

CVE-2026-56003 libXfont2 computeProps Property Buffer Heap Buffer Overflow

Information published.

INFOMSRCJul 09, 2026#457

CVE-2026-56001 libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow

Information published.

INFOMSRCJul 09, 2026#458

CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Information published.

INFOMSRCJul 09, 2026#459

CVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

Information published.

CRITICALMSRCJul 09, 2026#460

CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

Information published.

INFOMSRCJul 09, 2026#461

CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

Information published.

HIGHMSRCJul 09, 2026#462

CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Information published.

INFOMSRCJul 09, 2026#463

CVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

Information published.

INFOMSRCJul 09, 2026#464

CVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

Information published.

INFODRJul 09, 2026#465

European Organizations Have a Collaboration Security Confidence Gap

A new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.

HIGHBCJul 09, 2026#466

AssuranceAmerica data breach exposes records of 6.9 million drivers

American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year.  [...]

INFOTHNJul 09, 2026#467

Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accou...

CRITICALBCJul 09, 2026#468

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]

CRITICALTHNJul 09, 2026#469

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now...

INFOTHNJul 09, 2026#470

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-look...

INFOTHNJul 09, 2026#471

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 loo...

INFODRJul 08, 2026#472

Mexico's New Cyber Plan Faces Its First Real Test

The Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup.

HIGHBCJul 08, 2026#473

Mount Royal University confirms breach as hackers claim attack

Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]

HIGHDRJul 08, 2026#474

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.

HIGHBCJul 08, 2026#475

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]

HIGHBCJul 08, 2026#476

Hackers exploit Roundcube flaw to spy on academic researchers

A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. [...]

HIGHTHNJul 08, 2026#477

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicio...

INFOBCJul 08, 2026#478

Entra passkey enrollment vishing targets Microsoft 365 users

A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. [...]

HIGHDRJul 08, 2026#479

Vidar Infostealer Hammers SMBs via Malvertising Campaign

A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.

HIGHTHNJul 08, 2026#480

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call H...

CRITICALTHNJul 08, 2026#481

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command exec...

HIGHBCJul 08, 2026#482

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Specops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verificat...

HIGHTHNJul 08, 2026#483

New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life ...

HIGHTHNJul 08, 2026#484

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under th...

CRITICALKREBSJul 08, 2026#485

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures inc...

INFOBCJul 08, 2026#486

DuckDuckGo browser now blocks YouTube video ads

DuckDuckGo announced that its browser can now block most video ads on YouTube, including those shown before the video starts playing and during playback. [...]

INFOTHNJul 08, 2026#487

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with th...

HIGHTHNJul 08, 2026#488

The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for def...

HIGHBCJul 08, 2026#489

Telco giant KDDI says data breach affects over 12 million people

Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country...

INFOTHNJul 08, 2026#490

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a ...

CRITICALBCJul 08, 2026#491

CISA orders feds to prioritize patching Langflow auth bypass flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

HIGHTHNJul 08, 2026#492

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco...

CRITICALBCJul 08, 2026#493

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. [...]

INFODRJul 08, 2026#494

State IDs for AI Agents: Will Estonia Set a Precedent?

The world's digital testing ground plans to help people use AI agents for government purposes.

CRITICALBCJul 08, 2026#495

CISA orders feds to patch max severity ColdFusion flaw by Friday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Fri...

MEDIUMTHNJul 08, 2026#496

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. T...

CRITICALTHNJul 08, 2026#497

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are...

CRITICALBCJul 07, 2026#498

Accenture confirms breach after hacker offers stolen data for sale

IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]

HIGHDRJul 07, 2026#499

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

The phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.

INFODRJul 07, 2026#500

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security.

HIGHBCJul 07, 2026#501

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]

HIGHBCJul 07, 2026#502

Hidden backdoor in Tenda router firmware grants admin access

A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]

HIGHTHNJul 07, 2026#503

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the ...

CRITICALTHNJul 07, 2026#504

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could r...

HIGHDRJul 07, 2026#505

'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows

The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.

INFOBCJul 07, 2026#506

Spain arrests suspected member of pro-Russian hacktivist groups

The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]

HIGHTHNJul 07, 2026#507

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. ...

HIGHTHNJul 07, 2026#508

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a...

HIGHBCJul 07, 2026#509

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [.....

HIGHMSRCJul 07, 2026#510

CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Updated an acknowledgement. This is an informational change only.

HIGHTHNJul 07, 2026#511

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID...

CRITICALTHNJul 07, 2026#512

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant comp...

HIGHBCJul 07, 2026#513

Webinar tomorrow: Why modern email attacks require a new approach to defense

Tomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and...

HIGHBCJul 07, 2026#514

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. [...]

CRITICALTHNJul 07, 2026#515

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, wh...

INFOBCJul 07, 2026#516

Microsoft to enable Windows settings backup by default for orgs

Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. [...]

CRITICALTHNJul 07, 2026#517

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The...

INFOMSRCJul 07, 2026#518

CVE-2026-9080 UAF after pause in socket callback

Information published.

INFOMSRCJul 07, 2026#519

CVE-2026-8926 password leak with netrc and user in URL

Information published.

INFOMSRCJul 07, 2026#520

CVE-2026-10536 HTTP/2 stream-dependency tree UAF

Information published.

INFOMSRCJul 07, 2026#521

CVE-2026-8286 wrong STARTTLS connection reuse

Information published.

INFOMSRCJul 07, 2026#522

CVE-2026-8458 wrong reuse for different services

Information published.

INFOMSRCJul 07, 2026#523

CVE-2026-8924 trailing dot domain super cookie

Information published.

INFOMSRCJul 07, 2026#524

CVE-2026-8932 incomplete mTLS config matching in conn reuse

Information published.

INFOMSRCJul 07, 2026#525

CVE-2026-9545 exposing HTTP/3 early data

Information published.

INFOMSRCJul 07, 2026#526

CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Information published.

INFOMSRCJul 07, 2026#527

CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

Information published.

CRITICALBCJul 07, 2026#528

BeyondTrust warns of critical flaws in remote access software

BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]

INFOMSRCJul 07, 2026#529

CVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds

Information published.

INFOMSRCJul 07, 2026#530

CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras

Information published.

INFOMSRCJul 07, 2026#531

CVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl

Information published.

INFOMSRCJul 07, 2026#532

CVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loop

Information published.

INFOMSRCJul 07, 2026#533

CVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension

Information published.

INFOBCJul 07, 2026#534

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. [...]

HIGHTHNJul 07, 2026#535

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interf...

CRITICALTHNJul 07, 2026#536

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to ...

CRITICALDRJul 06, 2026#537

'BusySnake' Infostealer Slithers into Critical Infrastructure Networks

A threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.

HIGHDRJul 06, 2026#538

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).

HIGHBCJul 06, 2026#539

Phishing poses as big-brand job interview to steal Google accounts

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]

HIGHBCJul 06, 2026#540

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]

INFOTHNJul 06, 2026#541

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Isr...

INFOBCJul 06, 2026#542

Vietnam arrests suspects behind HiAnime anime piracy service

​Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]

HIGHTHNJul 06, 2026#543

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the f...

CRITICALDRJul 06, 2026#544

JadePuffer: The First Complete LLM-Driven Ransomware Attack

An "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.

CRITICALTHNJul 06, 2026#545

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerab...

INFOBCJul 06, 2026#546

Software Is Now Written at the Speed of Thought. Security Isn't.

Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have tradit...

HIGHBCJul 06, 2026#547

Max severity Adobe ColdFusion flaw now exploited in attacks

Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. [...]

CRITICALTHNJul 06, 2026#548

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home dev...

INFOTHNJul 06, 2026#549

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions

Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted o...

HIGHTHNJul 06, 2026#550

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from comprom...

HIGHTHNJul 06, 2026#551

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot se...

HIGHTHNJul 06, 2026#552

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware...

MEDIUMTHNJul 06, 2026#553

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. ...

HIGHTHNJul 06, 2026#554

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University...

INFOBCJul 05, 2026#555

Flipper Zero firmware development continues with community help

Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]

CRITICALBCJul 04, 2026#556

JadePuffer ransomware used AI agent to automate entire attack

Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]

CRITICALTHNJul 04, 2026#557

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail th...

INFOTHNJul 04, 2026#558

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing...

INFOMSRCJul 04, 2026#559

CVE-2026-53223 net: guard timestamp cmsgs to real error queue skbs

Information published.

MEDIUMTHNJul 03, 2026#560

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter...

INFOTHNJul 03, 2026#561

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out...

CRITICALTHNJul 03, 2026#562

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security control...

INFOBCJul 03, 2026#563

NetNut proxy network disrupted, 2 million infected devices cut off

A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]

INFOTHNJul 03, 2026#564

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "r...

HIGHBCJul 03, 2026#565

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsof...

HIGHMSRCJul 03, 2026#566

Chromium: CVE-2026-13797 Insufficient validation of untrusted input in Chromecast

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#567

Chromium: CVE-2026-13794 Insufficient validation of untrusted input in WebAppInstalls

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#568

Chromium: CVE-2026-14125 Uninitialized Use in ANGLE

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

CRITICALMSRCJul 03, 2026#569

Chromium: CVE-2026-13793 Insufficient policy enforcement in SVG

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#570

Chromium: CVE-2026-13790 Side-channel information leakage in Scroll

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#571

Chromium: CVE-2026-13787 Use after free in Chromoting

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#572

Chromium: CVE-2026-13786 Use after free in Ozone

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#573

Chromium: CVE-2026-13784 Use after free in Views

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#574

Chromium: CVE-2026-13783 Use after free in Views

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#575

Chromium: CVE-2026-13782 Use after free in Browser

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#576

Chromium: CVE-2026-13781 Insufficient validation of untrusted input in Skia

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#577

Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLE

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

CRITICALMSRCJul 03, 2026#578

Chromium: CVE-2026-13933 Insufficient policy enforcement in Passwords

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#579

Chromium: CVE-2026-13779 Use after free in Chromoting

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#580

Chromium: CVE-2026-13776 Type Confusion in Dawn

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#581

Chromium: CVE-2026-13775 Use after free in GPU

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#582

Chromium: CVE-2026-13814 Use after free in Views

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#583

Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settings

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#584

Chromium: CVE-2026-13828 Inappropriate implementation in Enterprise

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#585

Chromium: CVE-2026-13824 Insufficient validation of untrusted input in Extensions

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#586

Chromium: CVE-2026-13823 Use after free in Glic

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#587

Chromium: CVE-2026-13821 Use after free in Canvas

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#588

Chromium: CVE-2026-13820 Out of bounds read in Skia

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#589

Chromium: CVE-2026-13818 Inappropriate implementation in Passwords

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#590

Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glic

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#591

Chromium: CVE-2026-13815 Use after free in Blink

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#592

Chromium: CVE-2026-13811 Use after free in IME

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#593

Chromium: CVE-2026-13810 Inappropriate implementation in Input

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#594

Chromium: CVE-2026-13804 Use after free in Chromecast

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#595

Chromium: CVE-2026-13803 Type Confusion in Chrome Tabs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#596

Chromium: CVE-2026-13802 Use after free in Views

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#597

Chromium: CVE-2026-13801 Integer overflow in Chromecast

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

HIGHMSRCJul 03, 2026#598

Chromium: CVE-2026-14153 Inappropriate implementation in Glic

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information...

CRITICALMSRCJul 03, 2026#599

CVE-2026-55945 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CRITICALMSRCJul 03, 2026#600

CVE-2026-56645 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 03, 2026#601

CVE-2026-57975 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 03, 2026#602

CVE-2026-57983 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CRITICALMSRCJul 03, 2026#603

CVE-2026-57984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 03, 2026#604

CVE-2026-57985 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 03, 2026#605

CVE-2026-57987 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CRITICALMSRCJul 03, 2026#606

CVE-2026-57988 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 03, 2026#607

CVE-2026-57992 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 03, 2026#608

CVE-2026-57993 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

HIGHMSRCJul 03, 2026#609

CVE-2026-56646 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

HIGHMSRCJul 03, 2026#610

CVE-2026-58282 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CRITICALMSRCJul 03, 2026#611

CVE-2026-58283 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CRITICALMSRCJul 03, 2026#612

CVE-2026-58287 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CRITICALMSRCJul 03, 2026#613

CVE-2026-58299 Microsoft Edge for Android Remote Code Execution Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

HIGHMSRCJul 03, 2026#614

CVE-2026-58522 Microsoft Edge for Android Information Disclosure Vulnerability

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

HIGHTHNJul 03, 2026#615

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends...

HIGHDRJul 03, 2026#616

Chinese LLMs Broaden the Gap Between Attackers & Defenders

Two new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried?

HIGHTHNJul 03, 2026#617

European Parliament Member Investigating Spyware Was Hacked With Pegasus

A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that ...

INFOMSRCJul 03, 2026#618

CVE-2026-53296 mailbox: mailbox-test: free channels on probe error

Information published.

INFOMSRCJul 03, 2026#619

CVE-2026-53320 nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()

Information published.

INFOMSRCJul 03, 2026#620

CVE-2026-0864 Configuration Injection via Carriage Return (\r) in write() method

Information published.

INFOMSRCJul 03, 2026#621

CVE-2026-3195 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)

Information published.

INFOMSRCJul 03, 2026#622

CVE-2026-11972 tarfile opened in streaming mode mishandles EOF

Information published.

INFOMSRCJul 03, 2026#623

CVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

Information published.

INFOMSRCJul 03, 2026#624

CVE-2026-56405 libexpat before 2.8.2 has an integer overflow in getAttributeId.

Information published.

INFOMSRCJul 03, 2026#625

CVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

Information published.

INFOMSRCJul 03, 2026#626

CVE-2026-56403 libexpat before 2.8.2 has an integer overflow in storeAtts.

Information published.

INFOMSRCJul 03, 2026#627

CVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

Information published.

INFOMSRCJul 03, 2026#628

CVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

Information published.

INFOMSRCJul 03, 2026#629

CVE-2026-56404 libexpat before 2.8.2 has an integer overflow in addBinding.

Information published.

INFOMSRCJul 03, 2026#630

CVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

Information published.

INFOMSRCJul 03, 2026#631

CVE-2026-53016 crypto: ccp - copy IV using skcipher ivsize

Information published.

INFOMSRCJul 03, 2026#632

CVE-2026-53046 ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine

Information published.

INFOMSRCJul 03, 2026#633

CVE-2026-53039 ocfs2: validate group add input before caching

Information published.

INFOMSRCJul 03, 2026#634

CVE-2026-53045 memory: tegra124-emc: Fix dll_change check

Information published.

INFOMSRCJul 03, 2026#635

CVE-2026-53049 gfs2: add some missing log locking

Information published.

INFOMSRCJul 03, 2026#636

CVE-2026-53098 wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()

Information published.

INFOMSRCJul 03, 2026#637

CVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image

Information published.

INFOMSRCJul 03, 2026#638

CVE-2026-52911 ksmbd: scope conn->binding slowpath to bound sessions only

Information published.

HIGHMSRCJul 03, 2026#639

CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()

Information published.

INFOMSRCJul 03, 2026#640

CVE-2026-53052 ASoC: qcom: qdsp6: topology: check widget type before accessing data

Information published.

INFOMSRCJul 03, 2026#641

CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling

Information published.

INFOMSRCJul 03, 2026#642

CVE-2025-15661 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c

Information published.

INFOMSRCJul 03, 2026#643

CVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c

Information published.

CRITICALTHNJul 03, 2026#644

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, i...

INFOMSRCJul 03, 2026#645

CVE-2026-55199 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler

Information published.

INFOMSRCJul 03, 2026#646

CVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions()

Information published.

INFOMSRCJul 03, 2026#647

CVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interface

Information published.

INFOMSRCJul 03, 2026#648

CVE-2026-53195 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()

Information published.

INFOMSRCJul 03, 2026#649

CVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE

Information published.

INFOMSRCJul 03, 2026#650

CVE-2026-53196 USB: serial: io_ti: fix heap overflow in get_manuf_info()

Information published.

INFOMSRCJul 03, 2026#651

CVE-2026-52962 ceph: fix a buffer leak in __ceph_setxattr()

Information published.

INFOMSRCJul 03, 2026#652

CVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial send

Information published.

INFOMSRCJul 03, 2026#653

CVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START

Information published.

INFOMSRCJul 03, 2026#654

CVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()

Information published.

INFOMSRCJul 03, 2026#655

CVE-2026-53048 gfs2: prevent NULL pointer dereference during unmount

Information published.

INFOMSRCJul 03, 2026#656

CVE-2026-53160 misc: fastrpc: fix use-after-free race in fastrpc_map_create

Information published.

CRITICALMSRCJul 03, 2026#657

CVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service

Information published.

INFOMSRCJul 03, 2026#658

CVE-2026-53010 ksmbd: fix use-after-free in smb2_open during durable reconnect

Information published.

CRITICALMSRCJul 03, 2026#659

CVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Information published.

INFOMSRCJul 03, 2026#660

CVE-2026-53097 wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()

Information published.

INFOMSRCJul 03, 2026#661

CVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()

Information published.

INFOMSRCJul 03, 2026#662

CVE-2026-52954 libceph: handle rbtree insertion error in decode_choose_args()

Information published.

INFOMSRCJul 03, 2026#663

CVE-2026-52946 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling

Information published.

INFOBCJul 03, 2026#664

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

Anthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon. [...]

INFOBCJul 03, 2026#665

Claude Fable relaunch disappoints users with nerfed performance

Claude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release. [...]

INFODRJul 02, 2026#666

Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs

Improved institutional safeguards and stricter regulations have pushed the burdens of protection and risk reduction on to Australian businesses.

HIGHDRJul 02, 2026#667

Apple Reverses Age-Old Patch Policy to Keep Up With AI

Expect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit.

INFOKREBSJul 02, 2026#668

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli com...

CRITICALDRJul 02, 2026#669

FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.

INFOTHNJul 02, 2026#670

Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic. Working with the FBI, Lumen, and others, Google's Threat Intelligence Group (G...

CRITICALTHNJul 02, 2026#671

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common ...

CRITICALDRJul 02, 2026#672

Ransomware Thugs Masquerade as Interpol to Entice Small Biz

The ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere.

CRITICALTHNJul 02, 2026#673

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds...

INFOBCJul 02, 2026#674

Google loses final appeal to overturn €4.1 billion EU fine

Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...

HIGHBCJul 02, 2026#675

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]

HIGHTHNJul 02, 2026#676

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the attackers ...

CRITICALDRJul 02, 2026#677

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open-source software supply chain.

INFOBCJul 02, 2026#678

Microsoft fixes bug that removed Copilot buttons in Outlook

Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. [...]

HIGHBCJul 02, 2026#679

Cisco finally confirms attackers exploiting Unified CM flaw

Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]

INFOTHNJul 02, 2026#680

Identity Lifecycle Management Wasn't Built for AI Agents

Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments,...

CRITICALBCJul 02, 2026#681

CISA: Microsoft SharePoint RCE flaw now actively exploited

CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]

HIGHBCJul 02, 2026#682

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. [...]

CRITICALTHNJul 02, 2026#683

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language ...

INFOBCJul 02, 2026#684

Alleged Scattered Spider hacker extradited to the United States

A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]

CRITICALTHNJul 02, 2026#685

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An o...

HIGHTHNJul 02, 2026#686

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that clai...

CRITICALTHNJul 02, 2026#687

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of acti...

HIGHBCJul 02, 2026#688

Medtronic notifies customers impacted by ShinyHunters data breach

Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]

CRITICALBCJul 01, 2026#689

FortiBleed credential-theft campaign linked to Lynx ransomware

The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]

INFOBCJul 01, 2026#690

Kubota says hackers had month-long access to network systems

Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]

HIGHDRJul 01, 2026#691

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.

HIGHBCJul 01, 2026#692

New ChocoPoC malware targets researchers via trojanized PoC exploits

Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to ta...

HIGHDRJul 01, 2026#693

And the Winner in Dominant Malware Delivery? ClickFix

Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.

HIGHTHNJul 01, 2026#694

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal networ...

INFOTHNJul 01, 2026#695

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced ...

INFOTHNJul 01, 2026#696

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a "massive, multi-domain, multi-language" campaign that distribut...

HIGHBCJul 01, 2026#697

DHS confirms hackers breached HSIN info-sharing platform

The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-se...

HIGHTHNJul 01, 2026#698

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. The activity has been codenamed VE...

HIGHBCJul 01, 2026#699

Webinar: Why traditional email security is no longer enough

Modern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webina...

INFOBCJul 01, 2026#700

Hackers target Microsoft 365 accounts with 81 million login attempts

An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. [...]

INFODRJul 01, 2026#701

When Too Much Security Data Became the Risk

Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.

HIGHTHNJul 01, 2026#702

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet's FortiGuard Labs identified the campaign in May 2026. It opens with a phishing PDF disguised as ...

CRITICALTHNJul 01, 2026#703

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates "resolves critical and important vulnerabilities that could lead to a...

HIGHDRJul 01, 2026#704

'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat

LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.

CRITICALTHNJul 01, 2026#705

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall for and no approval bo...

HIGHBCJul 01, 2026#706

Turning Indicators into Intelligence in OpenCTI with Criminal IP

Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. [...]

HIGHMSRCJul 01, 2026#707

CVE-2026-32208 Microsoft Entra ID Spoofing Vulnerability

Corrected the CVE description and title. This is an informational change only.

CRITICALTHNJul 01, 2026#708

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity comp...

INFODRJul 01, 2026#709

Safe Events Start With Threat Intel and Digital Security

Planning ahead to defend against cyber threats is the work that keeps events uneventful.

CRITICALTHNJul 01, 2026#710

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into ...

CRITICALBCJul 01, 2026#711

Over 900 Oracle E-Business instances exposed to ongoing attacks

Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]

INFOTHNJul 01, 2026#712

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

Organizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging. The 2026 Bitdefender Cybersecurity Assessment confirms this is the cas...

INFOBCJul 01, 2026#713

Microsoft fixes GIF functionality in the Windows Emoji Panel

Microsoft has fixed the GIF functionality in the Emoji Panel for Windows 11 users after the provider shut down its service. [...]

INFOTHNJul 01, 2026#714

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expe...

INFOBCJul 01, 2026#715

Amazon fined $2.25M for withholding evidence from fraud victims

The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records. [...]

INFOMSRCJul 01, 2026#716

CVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

Information published.

INFOMSRCJul 01, 2026#717

CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing

Information published.

INFOMSRCJul 01, 2026#718

CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring

Information published.

INFOMSRCJul 01, 2026#719

CVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery

Information published.

INFOMSRCJul 01, 2026#720

CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status

Information published.

INFOMSRCJul 01, 2026#721

CVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block size

Information published.

INFOMSRCJul 01, 2026#722

CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation

Information published.

INFOMSRCJul 01, 2026#723

CVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field element

Information published.

INFOMSRCJul 01, 2026#724

CVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checks

Information published.

INFOMSRCJul 01, 2026#725

CVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchor

Information published.

INFOMSRCJul 01, 2026#726

CVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list

Information published.

INFOMSRCJul 01, 2026#727

CVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage

Information published.

INFOMSRCJul 01, 2026#728

CVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS name

Information published.

INFOMSRCJul 01, 2026#729

CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be accepted

Information published.

INFOMSRCJul 01, 2026#730

CVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the input

Information published.

INFOMSRCJul 01, 2026#731

CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal

Information published.

INFOMSRCJul 01, 2026#732

CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData

Information published.

INFOMSRCJul 01, 2026#733

CVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info

Information published.

INFOMSRCJul 01, 2026#734

CVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer

Information published.

HIGHMSRCJul 01, 2026#735

CVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison length

Information published.

INFOMSRCJul 01, 2026#736

CVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()

Information published.

INFOMSRCJul 01, 2026#737

CVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify

Information published.

INFOMSRCJul 01, 2026#738

CVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse

Information published.

INFOMSRCJul 01, 2026#739

CVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption

Information published.

INFOMSRCJul 01, 2026#740

CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)

Information published.

INFOMSRCJul 01, 2026#741

CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation

Information published.

CRITICALMSRCJul 01, 2026#742

CVE-2026-6450 CRL critical extension bypass in ParseCRL_Extensions

Information published.

CRITICALMSRCJul 01, 2026#743

CVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined

Information published.

INFOMSRCJul 01, 2026#744

CVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption

Information published.

INFOMSRCJul 01, 2026#745

CVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

Information published.

INFOMSRCJul 01, 2026#746

CVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the container

Information published.

INFOMSRCJul 01, 2026#747

CVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces

Information published.

INFOMSRCJul 01, 2026#748

CVE-2026-13218 Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher

Information published.

INFOMSRCJul 01, 2026#749

CVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body

Information published.

INFOMSRCJul 01, 2026#750

CVE-2026-13318 Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip

Information published.

INFOMSRCJul 01, 2026#751

CVE-2026-13322 Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service

Information published.

INFOMSRCJul 01, 2026#752

CVE-2026-58014 Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

Information published.

INFOMSRCJul 01, 2026#753

CVE-2026-58013 Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

Information published.

INFOMSRCJul 01, 2026#754

CVE-2026-58011 Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Information published.

INFOMSRCJul 01, 2026#755

CVE-2026-58012 Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Information published.

INFOMSRCJul 01, 2026#756

CVE-2026-58016 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

Information published.

INFOMSRCJul 01, 2026#757

CVE-2026-58015 Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Information published.

INFOMSRCJul 01, 2026#758

CVE-2026-58010 Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()

Information published.

INFOMSRCJul 01, 2026#759

CVE-2026-48779 ws: Memory exhaustion DoS from tiny fragments and data chunks

Information published.

HIGHMSRCJul 01, 2026#760

CVE-2026-42055 NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

Information published.

MEDIUMBCJul 01, 2026#761

Adobe patches seven max severity ColdFusion, Campaign flaws

Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. [...]

HIGHTHNJul 01, 2026#762

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point t...

CRITICALTHNJul 01, 2026#763

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a...

HIGHTHNJul 01, 2026#764

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per H...

HIGHTHNJul 01, 2026#765

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven ...

HIGHTHNJul 01, 2026#766

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary ...

CRITICALDRJul 01, 2026#767

China-Linked Group Targets Southeast Asia Critical Systems

The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

CRITICALBCJul 01, 2026#768

Anthropic to restore Claude Fable access on Wednesday

Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]

INFOBCJun 30, 2026#769

Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price

Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]

HIGHBCJun 30, 2026#770

New BioShocking attack manipulates AI browser into data theft

A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]

HIGHDRJun 30, 2026#771

Fake Bug Report Hijacks AI Coding Agents at Scale

"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.

INFOBCJun 30, 2026#772

Microsoft accelerates quantum-safe roadmap as risks grow

Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. [.....

HIGHBCJun 30, 2026#773

Malicious PyPI packages give hackers control of Telegram bot servers

A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]

HIGHDRJun 30, 2026#774

Attackers Seize Exposed AI Endpoints to Power Offensive Ops

Threat actors don't need any special authentication to reach a target endpoint — they just need to know where it is.

INFODRJun 30, 2026#775

Why Identity Security Is Your Cyber Career Entry Point

As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential...

HIGHDRJun 30, 2026#776

Phishers Gain Persistence at EU, Asia Hospitality Orgs

Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.

HIGHTHNJun 30, 2026#777

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. ...

HIGHTHNJun 30, 2026#778

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Re...

CRITICALTHNJun 30, 2026#779

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: ...

CRITICALBCJun 30, 2026#780

Fake Perplexity extension on Chrome Web Store tracked searches

A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]

INFOTHNJun 30, 2026#781

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocur...

CRITICALTHNJun 30, 2026#782

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is...

HIGHBCJun 30, 2026#783

Lessons from the Underground: How to Combat Business Email Compromise

Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks a...

INFOTHNJun 30, 2026#784

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app...

INFODRJun 30, 2026#785

AI-Generated Workflows Are a Silent Security Disaster

Teams are dealing with a truly dangerous problem — automation that works, but that no one understands.

INFOTHNJun 30, 2026#786

What the Numbers Say About FIFA 2026 Cyber Risk

The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-plan...

CRITICALTHNJun 30, 2026#787

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion i...

HIGHBCJun 30, 2026#788

Insurance giant Aflac discloses data breach after subsidiary hack

American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information. [...]

INFOBCJun 30, 2026#789

Microsoft adds smarter bot protection to Teams meetings

Microsoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. [...]

INFOBCJun 30, 2026#790

Microsoft adds smarter bot protection to Teams meetings

Microsoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. [...]

MEDIUMBCJun 30, 2026#791

Kali Linux 2026.2 released with 9 new tools, NetHunter updates

Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]

CRITICALBCJun 30, 2026#792

Blackfield ransomware asks Nidec Corporation for $2 million ransom

The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. [...]

HIGHTHNJun 30, 2026#793

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a lap...

CRITICALBCJun 30, 2026#794

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]

HIGHTHNJun 30, 2026#795

New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants in...

INFOMSRCJun 30, 2026#796

CVE-2026-11979 Stack-Based Buffer Overflow in libxml2

Information published.

INFOMSRCJun 30, 2026#797

CVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe()

Information published.

INFOMSRCJun 30, 2026#798

CVE-2026-41992 Global Buffer Overflow in GNU gzip

Information published.

INFOMSRCJun 30, 2026#799

CVE-2026-41991 Predictable Temporary File in GNU gzip

Information published.

INFOMSRCJun 30, 2026#800

CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr

Information published.

INFOMSRCJun 30, 2026#801

CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

Information published.

CRITICALTHNJun 30, 2026#802

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-80...

CRITICALTHNJun 30, 2026#803

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an imprope...

INFODRJun 29, 2026#804

NIST Enrichment Reductions Impact CVE Coverage, Accuracy

The National Institute of Standards and Technology (NIST) scaled back the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers.

CRITICALDRJun 29, 2026#805

'Djinn' Stealer Targets Cloud, AI Credentials

The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.

CRITICALDRJun 29, 2026#806

Vulnerabilities Expose Private Data in Indian Government Systems

One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.

CRITICALBCJun 29, 2026#807

Nissan discloses employee data breach linked to Oracle zero-day attacks

Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extorti...

CRITICALBCJun 29, 2026#808

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero...

INFODRJun 29, 2026#809

Can Clothes Make You Invisible to Facial Recognition?

Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras.

HIGHDRJun 29, 2026#810

Iran, Russia, China Target Water Systems for Sabotage

Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware.

INFOBCJun 29, 2026#811

WhatsApp rolls out usernames to help users hide their phone number

WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]

MEDIUMBCJun 29, 2026#812

Microsoft extends Windows Server 2022 hotpatching until October 2027

Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. [...]

INFOTHNJun 29, 2026#813

WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private

WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to he...

CRITICALTHNJun 29, 2026#814

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an ...

MEDIUMTHNJun 29, 2026#815

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) too...

INFOBCJun 29, 2026#816

U.S. offers $10 million for hackers targeting WhatsApp, Signal users

The U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services. ...

HIGHTHNJun 29, 2026#817

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command chann...

HIGHTHNJun 29, 2026#818

⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, res...

HIGHBCJun 29, 2026#819

Agentic AI Has an Identity Problem and Attackers Know It

AI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security. [...]

CRITICALBCJun 29, 2026#820

Critical SimpleHelp flaw exploited to deploy new stealer malware

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux....

CRITICALBCJun 29, 2026#821

Hackers now exploit critical Oracle E-Business flaw in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. [...]

HIGHBCJun 29, 2026#822

Webinar: Why business email compromise attacks keep succeeding

Business email compromise attacks increasingly rely on convincing impersonation rather than malware, making them harder for employees and traditional email defenses to detect. This webinar explores how behavioral AI can ...

CRITICALTHNJun 29, 2026#823

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni...

HIGHDRJun 29, 2026#824

Amazon Q VS Extension Flaw Leads to Cloud Credential Theft

Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk.

INFOTHNJun 29, 2026#825

Why Post-Quantum Cryptography Starts With Credentials

Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break...

HIGHTHNJun 29, 2026#826

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said i...

INFOBCJun 29, 2026#827

US seizes hundreds of FIFA World Cup illegal streaming domains

The U.S. Justice Department's Criminal Division has seized nearly 400 web domains used for illegally streaming matches at the FIFA World Cup. [...]

HIGHTHNJun 29, 2026#828

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad f...

INFOMSRCJun 29, 2026#829

CVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header Parsing

Information published.

INFOMSRCJun 29, 2026#830

CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length

Information published.

INFOMSRCJun 29, 2026#831

CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup

Information published.

INFOMSRCJun 29, 2026#832

CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation

Information published.

INFOMSRCJun 29, 2026#833

CVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible

Information published.

INFOMSRCJun 29, 2026#834

CVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.

Information published.

INFOMSRCJun 29, 2026#835

CVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.

Information published.

CRITICALTHNJun 29, 2026#836

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No crede...

HIGHTHNJun 29, 2026#837

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack...

HIGHBCJun 28, 2026#838

Data breach exposes up to 14.2 million email logins at six ISPs

Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]

INFOMSRCJun 28, 2026#839

CVE-2024-53201 drm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe

Information published.

INFOMSRCJun 28, 2026#840

CVE-2023-52485 drm/amd/display: Wake DMCUB before sending a command

Information published.

INFOMSRCJun 28, 2026#841

CVE-2026-23207 spi: tegra210-quad: Protect curr_xfer check in IRQ handler

Information published.

INFOMSRCJun 28, 2026#842

CVE-2025-38029 kasan: avoid sleepable page allocation from atomic context

Information published.

INFOMSRCJun 28, 2026#843

CVE-2025-38064 virtio: break and reset virtio devices on device_shutdown()

Information published.

INFOMSRCJun 28, 2026#844

CVE-2024-53114 x86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client

Information published.

INFOMSRCJun 28, 2026#845

CVE-2025-38041 clk: sunxi-ng: h616: Reparent GPU clock during frequency changes

Information published.

INFOMSRCJun 28, 2026#846

CVE-2025-21870 ASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers

Information published.

INFOMSRCJun 28, 2026#847

CVE-2025-71227 wifi: mac80211: don't WARN for connections on invalid channels

Information published.

INFOMSRCJun 28, 2026#848

CVE-2025-21888 RDMA/mlx5: Fix a WARN during dereg_mr for DM type

Information published.

INFOMSRCJun 28, 2026#849

CVE-2026-23214 btrfs: reject new transactions if the fs is fully read-only

Information published.

INFOMSRCJun 28, 2026#850

CVE-2025-71225 md: suspend array while updating raid_disks via sysfs

Information published.

INFOMSRCJun 28, 2026#851

CVE-2026-23213 drm/amd/pm: Disable MMIO access during SMU Mode 1 reset

Information published.

INFOMSRCJun 28, 2026#852

CVE-2025-40213 Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete

Information published.

INFOMSRCJun 28, 2026#853

CVE-2026-0989 Libxml2: unbounded relaxng include recursion leading to stack overflow

Information published.

INFOMSRCJun 28, 2026#854

CVE-2025-71072 shmem: fix recovery on rename failures

Information published.

INFOMSRCJun 28, 2026#855

CVE-2025-71073 Input: lkkbd - disable pending work before freeing device

Information published.

INFOMSRCJun 28, 2026#856

CVE-2025-68822 Input: alps - fix use-after-free bugs caused by dev3_register_work

Information published.

INFOMSRCJun 28, 2026#857

CVE-2025-68374 md: fix rcu protection in md_wakeup_thread

Information published.

INFOMSRCJun 28, 2026#858

CVE-2025-68378 bpf: Fix stackmap overflow check in __bpf_get_stackid()

Information published.

INFOMSRCJun 28, 2026#859

CVE-2025-68745 scsi: qla2xxx: Clear cmds after chip reset

Information published.

INFOMSRCJun 28, 2026#860

CVE-2025-68338 net: dsa: microchip: Don't free uninitialized ksz_irq

Information published.

INFOMSRCJun 28, 2026#861

CVE-2025-68304 Bluetooth: hci_core: lookup hci_conn on RX path on protocol side

Information published.

INFOMSRCJun 28, 2026#862

CVE-2025-68188 tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()

Information published.

INFOMSRCJun 28, 2026#863

CVE-2025-68209 mlx5: Fix default values in create CQ

Information published.

INFOMSRCJun 28, 2026#864

CVE-2025-40355 sysfs: check visibility before changing group attribute ownership

Information published.

INFOMSRCJun 28, 2026#865

CVE-2025-68174 amd/amdkfd: enhance kfd process check in switch partition

Information published.

INFOMSRCJun 28, 2026#866

CVE-2025-21885 RDMA/bnxt_re: Fix the page details for the srq created by kernel consumers

Information published.

INFOMSRCJun 28, 2026#867

CVE-2025-68230 drm/amdgpu: fix gpu page fault after hibernation on PF passthrough

Information published.

INFOMSRCJun 28, 2026#868

CVE-2025-68201 drm/amdgpu: remove two invalid BUG_ON()s

Information published.

INFOMSRCJun 28, 2026#869

CVE-2025-21892 RDMA/mlx5: Fix the recovery flow of the UMR QP

Information published.

INFOMSRCJun 28, 2026#870

CVE-2025-68190 drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()

Information published.

INFOMSRCJun 28, 2026#871

CVE-2025-40339 drm/amdgpu: fix nullptr err of vm_handle_moved

Information published.

INFOMSRCJun 28, 2026#872

CVE-2025-40289 drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM

Information published.

INFOMSRCJun 28, 2026#873

CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509

Information published.

HIGHMSRCJun 28, 2026#874

CVE-2023-6606 Kernel: out-of-bounds read vulnerability in smbcalcsize

Information published.

INFOMSRCJun 28, 2026#875

CVE-2025-40180 mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop

Information published.

INFOMSRCJun 28, 2026#876

CVE-2025-40158 ipv6: use RCU in ip6_output()

Information published.

INFOMSRCJun 28, 2026#877

CVE-2025-40170 net: use dst_dev_rcu() in sk_setup_caps()

Information published.

INFOMSRCJun 28, 2026#878

CVE-2025-40168 smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().

Information published.

INFOMSRCJun 28, 2026#879

CVE-2025-40146 blk-mq: fix potential deadlock while nr_requests grown

Information published.

INFOMSRCJun 28, 2026#880

CVE-2025-40139 smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().

Information published.

INFOMSRCJun 28, 2026#881

CVE-2024-53219 virtiofs: use pages instead of pointer for kernel direct IO

Information published.

INFOMSRCJun 28, 2026#882

CVE-2025-21825 bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT

Information published.

INFOMSRCJun 28, 2026#883

CVE-2024-1151 Kernel: stack overflow problem in open vswitch kernel module leading to dos

Information published.

INFOMSRCJun 28, 2026#884

CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment

Information published.

INFOMSRCJun 28, 2026#885

CVE-2025-21833 iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE

Information published.

INFOMSRCJun 28, 2026#886

CVE-2024-58089 btrfs: fix double accounting race when btrfs_run_delalloc_range() failed

Information published.

INFOMSRCJun 28, 2026#887

CVE-2024-25740 A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.

Information published.

HIGHMSRCJun 28, 2026#888

CVE-2024-24864 Race condition vulnerability in Linux kernel media/dvb-core in dvbdmx_write()

Information published.

HIGHTHNJun 27, 2026#889

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging acc...

HIGHBCJun 27, 2026#890

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]

INFOTHNJun 27, 2026#891

OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest fl...

CRITICALDRJun 27, 2026#892

Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk

Rising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks.

HIGHMSRCJun 27, 2026#893

Chromium: CVE-2026-13038 Use after free in Autofill

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#894

Chromium: CVE-2026-13036 Use after free in Blink

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#895

Chromium: CVE-2026-13035 Use after free in Bluetooth

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#896

Chromium: CVE-2026-13034 Inappropriate implementation in Passwords

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#897

Chromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroups

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#898

Chromium: CVE-2026-13031 Use after free in Blink

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#899

Chromium: CVE-2026-13029 Use after free in Web Authentication

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#900

Chromium: CVE-2026-13027 Use after free in FileSystem

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#901

Chromium: CVE-2026-13026 Use after free in Digital Credentials

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#902

Chromium: CVE-2026-13025 Insufficient validation of untrusted input in DevTools

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#903

Chromium: CVE-2026-13024 Insufficient validation of untrusted input in Navigation

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#904

Chromium: CVE-2026-13023 Uninitialized Use in GPU

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#905

Chromium: CVE-2026-13022 Inappropriate implementation in Autofill

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHMSRCJun 27, 2026#906

Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information...

HIGHBCJun 26, 2026#907

FBI: Russian hackers now target Signal backup recovery keys

The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messag...

CRITICALBCJun 26, 2026#908

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]

HIGHTHNJun 26, 2026#909

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery K...

INFODRJun 26, 2026#910

AI Decline? Confidence in Autonomous Penetration Testing Falls

Companies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology.

HIGHTHNJun 26, 2026#911

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky,...

HIGHBCJun 26, 2026#912

Polymarket customers lose $3 million in supply-chain attack

Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]

INFOBCJun 26, 2026#913

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats an...

CRITICALDRJun 26, 2026#914

Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions

Cisco joins a growing list of security platform providers that are betting that securing the agentic workforce means turning identity into the primary control plane.

CRITICALDRJun 26, 2026#915

New Initiative Tackles Security for End-of-Life Open Source Software

The Open Source Sustainability Initiative's goal is to help enterprises manage and secure aging open source projects while maintaining regulatory compliance.

CRITICALTHNJun 26, 2026#916

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The ...

INFODRJun 26, 2026#917

AI Won't Wipe-Out Entry-Level Cybersecurity Jobs

Instead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills.

INFOBCJun 26, 2026#918

Your First GRC Agent: A Red Teamer's Walkthrough

AI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation task...

HIGHTHNJun 26, 2026#919

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_...

MEDIUMTHNJun 26, 2026#920

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the re...

MEDIUMDRJun 26, 2026#921

Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex

Getting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps.

INFODRJun 26, 2026#922

Thanks for Crushing the Submissions Inbox. We're Trying to Keep Up

It might be taking a bit longer than usual to respond to your submissions — here's why.

CRITICALTHNJun 26, 2026#923

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) a...

HIGHTHNJun 26, 2026#924

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this va...

INFOTHNJun 26, 2026#925

Guardian Agents: The Next Layer of Identity Governance

AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access ...

HIGHTHNJun 26, 2026#926

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propa...

HIGHTHNJun 26, 2026#927

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, M...

INFOTHNJun 26, 2026#928

Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff

Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and ser...

INFOMSRCJun 26, 2026#929

CVE-2026-46320 tap: free page on error paths in tap_get_user_xdp()

Information published.

INFOMSRCJun 26, 2026#930

CVE-2026-46322 tun: free page on build_skb failure in tun_xdp_one()

Information published.

INFOMSRCJun 26, 2026#931

CVE-2026-46321 tun: free page on short-frame rejection in tun_xdp_one()

Information published.

INFOMSRCJun 26, 2026#932

CVE-2026-45930 net: mctp: ensure our nlmsg responses are initialised

Information published.

INFOMSRCJun 26, 2026#933

CVE-2026-45850 ipvs: skip ipv6 extension headers for csum checks

Information published.

INFOMSRCJun 26, 2026#934

CVE-2025-68736 landlock: Fix handling of disconnected directories

Information published.

INFOMSRCJun 26, 2026#935

CVE-2025-68296 drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup

Information published.

HIGHTHNJun 26, 2026#936

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and...

INFOBCJun 25, 2026#937

Anthropic is testing desktop-like Claude Cowork for mobile

Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]

INFODRJun 25, 2026#938

Robinhood Cuts Access Approval Time to Support High-Velocity Development

The fintech company's engineering-first application security team re-engineered the process for granting system access, making it easier and more secure for developers working on their projects. Here are the lessons lear...

HIGHBCJun 25, 2026#939

Poland busts SIM-swapping gang tied to millions in crypto theft

Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]

HIGHDRJun 25, 2026#940

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments.

HIGHDRJun 25, 2026#941

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.

HIGHDRJun 25, 2026#942

EdTech Attackers Shift From Schools to Their Software Suppliers

Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series.

HIGHBCJun 25, 2026#943

Order-tracking app Shop abused to push callback phishing attacks

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access softwar...

CRITICALDRJun 25, 2026#944

Local Police Collusion Hampers Crackdown on Asian Scam Centers

With tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.

MEDIUMBCJun 25, 2026#945

Microsoft quietly extends free Windows 10 ESU support to October 2027

Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [.....

HIGHBCJun 25, 2026#946

New macOS malware embeds fake errors to confuse AI analysis tools

A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]

INFOBCJun 25, 2026#947

PirloTV sports piracy network disrupted as 44 domains seized

A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]

HIGHBCJun 25, 2026#948

Bluekit phishing kit adopts browser-in-the-middle for login theft

The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]

INFOTHNJun 25, 2026#949

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndn...

HIGHBCJun 25, 2026#950

The Four Elevations of Effective Fraud Prevention

Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]

HIGHMSRCJun 25, 2026#951

CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability

Updated an acknowledgement. This is an informational change only.

HIGHMSRCJun 25, 2026#952

CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability

Updated an acknowledgement. This is an informational change only.

HIGHTHNJun 25, 2026#953

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, a...

HIGHBCJun 25, 2026#954

Webinar: Why account takeovers remain one of the hardest threats to stop

Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify comp...

INFOTHNJun 25, 2026#955

Surviving the Mythos Era: Richard Bejtlich on the Case for NDR

Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’...

CRITICALDRJun 25, 2026#956

Europe Evolves Into Ransomware's Favorite Region

After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.

HIGHTHNJun 25, 2026#957

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into abo...

HIGHTHNJun 25, 2026#958

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April ...

INFOMSRCJun 25, 2026#959

CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

Information published.

INFOMSRCJun 25, 2026#960

CVE-2026-11816 Path Traversal in keras-team/keras

Information published.

INFOMSRCJun 25, 2026#961

CVE-2026-46140 Bluetooth: btmtk: validate WMT event SKB length before struct access

Information published.

CRITICALTHNJun 25, 2026#962

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google...

INFOBCJun 24, 2026#963

Google releases new privacy controls for activity history, personalization

Google is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]

HIGHBCJun 24, 2026#964

DraftKings hacker 'Snoopy' sentenced to 18 months in prison

A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]

CRITICALBCJun 24, 2026#965

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]

HIGHDRJun 24, 2026#966

Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure

Researchers believe rogue peering was used to connect to the victim's SD-WAN devices to gain admin privileges and root-level access.

CRITICALBCJun 24, 2026#967

Malicious Edge extension abuses Native Messaging as bridge to malware

A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]

INFODRJun 24, 2026#968

2026 FIFA World Cup Faces Surge in Cyber Threats

Persistent cybercrime, social engineering, and infrastructure threats continue to plague the FIFA 2026 World Cup across the US, Canada, and Mexico.

INFODRJun 24, 2026#969

Do CISOs Need a Code of Ethics?

Dark Reading Confidential Episode 19: Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks it's time for a CISO code of ethics. It could ensure cybersecurit...

CRITICALTHNJun 24, 2026#970

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (...

INFODRJun 24, 2026#971

More Malicious OpenClaw Skills Threaten AI Supply Chain

OpenClaw removed five packages from its ClawHub skills marketplace that bypassed security checks even though they included infostealers and other threats.

CRITICALTHNJun 24, 2026#972

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and Ste...

HIGHBCJun 24, 2026#973

CISA warns of max severity Ubiquiti flaws exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]

CRITICALBCJun 24, 2026#974

Amadey, StealC malware operations disrupted in Operation Endgame action

Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]

CRITICALTHNJun 24, 2026#975

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cor...

HIGHDRJun 24, 2026#976

Apple's MacOS Gap Lets Users Disable Security Tools

Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.

MEDIUMTHNJun 24, 2026#977

Dawn of the Apex Agentic Adversary

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a ven...

INFOMSRCJun 24, 2026#978

CVE-2026-46285 mtd: docg3: fix use-after-free in docg3_release()

Information published.

INFOTHNJun 24, 2026#979

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering

The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanction...

CRITICALTHNJun 24, 2026#980

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). ...

CRITICALDRJun 23, 2026#981

Scope of Salesforce Attacks Expands as Icarus Leaks Data

More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.

INFODRJun 23, 2026#982

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.

INFOTHNJun 23, 2026#983

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls global...

HIGHKREBSJun 23, 2026#984

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Great...

INFOTHNJun 23, 2026#985

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill se...

INFOTHNJun 23, 2026#986

Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by D...

HIGHTHNJun 23, 2026#987

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code wit...

HIGHMSRCJun 23, 2026#988

CVE-2026-42915 Microsoft Windows VMSwitch Denial of Service Vulnerability

Updated an acknowledgement. This is an informational change only.

HIGHMSRCJun 23, 2026#989

CVE-2026-45504 Microsoft Exchange Server Elevation of Privilege Vulnerability

Acknowledgement added. This is an informational change only.

HIGHMSRCJun 23, 2026#990

CVE-2026-33840 Win32k Elevation of Privilege Vulnerability

Updated an acknowledgement. This is an informational change only.

INFODRJun 23, 2026#991

SocGholish Takedown Highlights Malicious TDS Threats

SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.

HIGHDRJun 23, 2026#992

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.

INFOTHNJun 23, 2026#993

Agentic AI: The Weapon That No Longer Needs a Warrior

Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, a...

HIGHTHNJun 23, 2026#994

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT

Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - aes-decode-runner-pro (1...

INFOTHNJun 23, 2026#995

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings fro...

MEDIUMTHNJun 23, 2026#996

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month. Calling GPT...

HIGHDRJun 22, 2026#997

DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories

Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.

HIGHTHNJun 22, 2026#998

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the ...

INFOTHNJun 22, 2026#999

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug t...

CRITICALTHNJun 22, 2026#1000

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial int...

HIGHDRJun 22, 2026#1001

Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign

Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.

HIGHDRJun 22, 2026#1002

He Thought He Was Secure; His Phone Number Was Stolen Anyway

Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures.

HIGHTHNJun 22, 2026#1003

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverag...

INFOTHNJun 22, 2026#1004

Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries

Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On that date, certifie...

HIGHTHNJun 22, 2026#1005

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy i...

CRITICALTHNJun 22, 2026#1006

⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More

It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much co...

INFOTHNJun 22, 2026#1007

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version ...

HIGHTHNJun 22, 2026#1008

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at ...

CRITICALTHNJun 22, 2026#1009

INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a dispar...

INFOSCHNEIER#1010

AI and Liability

Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information gener...

HIGHSCHNEIER#1011

Interesting Paper Exploring Prompt Injection

This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: ...

HIGHSCHNEIER#1012

Embedding Forbidden Text in Spyware to Discourage AI Analysis

At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details: The _index.js payload begins with a large JavaScript block comment...

HIGHSCHNEIER#1013

Anthropic’s Fable 5 Model Jailbroken Within Days

Fable 5 is the supposed safe version of Anthropic’s Mythos Preview, with guardrails to ensure that it can’t be used to create cyberattacks. Well, that restriction was bypassed within days.

INFOSCHNEIER#1014

Professional Athletes and Wearables

I haven’t thought about the privacy issues surrounding professional athletes and wearables. Wearables present serious privacy issues for “Average Joe” consumers, who are entrusting tech companies to saf...

INFOSCHNEIER#1015

Friday Squid Blogging: Victims of Unregulated Squid Fishing

Dolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article. As usual, you can also use this squid post to talk about the security stories in the news that I hav...

INFOSCHNEIER#1016

Anthropic’s Fable and the State of AI

On June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from acces...

HIGHSCHNEIER#1017

Embedding Forbidden Text in Spyware to Discourage AI Analysis

At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details: The _index.js payload begins with a large JavaScript block comment...

INFOSCHNEIER#1018

AI Use by the US Government

On 14 April, the Trump administration quietly acknowledged the widespread use of AI to automate government processes. The office of management and budget (OMB) disclosed a staggering 3,611 active or planned use cases for...

INFOSCHNEIER#1019

Flock Cameras Are Being Used for Stalking

There are over a dozen cases around the country where police officers are using the Flock surveillance camera system to obsessively and illegally stalk people. Alternate link.

INFOSCHNEIER#1020

One Million Passports Leaked Online

A database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verificati...

INFOSCHNEIER#1021

The Chinese Control the Majority of Argentina’s Squid Fleet

Chinese companies control nearly two-thirds of Argentina’s own squid fleet.

INFOSCHNEIER#1022

Meta Is Testing Facial Recognition for Police and Military

We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)

CRITICALSCHNEIER#1023

Factoring RSA Keys with Many Zeros

Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabili...

INFOSCHNEIER#1024

Robot Police Officers

We’ve taken one small step towards robot police officers: a drone capable of disarming a suspect: In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can...

INFOSCHNEIER#1025

The Realities of AI Video Surveillance

The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mas...

INFOSCHNEIER#1026

Papa Johns Surveillance-Based Advertising

Papa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers w...

INFOSCHNEIER#1027

Cybersecurity Mission Creep in the US

Interesting paper: “Cybersecurity Mission Creep.” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly differe...

CRITICALSCHNEIER#1028

Flock Cameras Can Surveil Cars Without License Plates

This is from a 2024 company presentation: Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags. Flock calls it a “Vehicl...

CRITICALSCHNEIER#1029

France to Stop Certifying Non-Quantum-Safe Encryption

France is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that w...

HIGHSCHNEIER#1030

Google Is Suing Chinese Scammers Who Are Using Gemini

Not sure this will have any effect, but I support the effort: According to Google’s legal filing, Outsider Enterprise operates through Telegram. The group offers phishing-as-a-service to individuals who may not be ...

MEDIUMSCHNEIER#1031

Cybersecurity and the Gap Between Skill and Ability

Last week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in par...

INFOSCHNEIER#1032

The Language of AI Could Change How Humans Speak

Because of the way they are trained, large language models capture only a slice of human language. They’re trained on the written word, from textbooks to social media posts, and our speech as captured in movies and...

HIGHSCHNEIER#1033

Friday Squid Blogging: “Squidbleed” Vulnerability

In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t c...

INFOSCHNEIER#1034

AI Surveillance and Social Progress

In the near future, AI-powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the...

INFOSCHNEIER#1035

AI Data Centers and the Concentration of Wealth

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall al...

INFOSCHNEIER#1036

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership...

HIGHSCHNEIER#1037

Vulnerability in FIFA’s Network

FIFA’s network was vulnerable to anyone with even minimal access.

INFOSCHNEIER#1038

A Video Screen That Is Also a Camera

Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light...

INFOSCHNEIER#1039

Protecting Privacy in an AI Era

Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable f...

INFOSCHNEIER#1040

Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

INFOSCHNEIER#1041

Details of Alan Turing’s Voice Encryption System

Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollar...

No articles match your filters
Try a different search term, time range, or severity