Cyber Security
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
23andMe Pays $18M to 43 State AGs Over Genetic Data Breach
Italy Fines WINDTRE €1.7M for Breaches Exposing 365K Customers
Interlock Hits DC Housing Authority; Play, Nova Post New Victims
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
PhantomEnigma Weaponizes 20+ Brazilian Gov Sites for Malware Delivery
Chinese Actors Weaponized Claude Code in Multi-Nation Espionage Op
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
CoinbaseCartel Hits Panasonic Avionics; Pear Targets US Healthcare
SonicWall SMA1000 CVSS 10.0 Zero-Day Hits Remote Access Gateways
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
DOJ Charges Three Russians Behind LockBit, Play Hosting Network
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
300 Fake GitHub Repos Deliver BoryptGrab Chrome Bypass Infostealer
Unpatched Claude for Chrome Flaw Exposes Gmail and Calendar Data
AsyncAPI npm Packages Backdoored to Deploy Miasma Botnet Loader
Spanish Police Break Up €140M BEC Ring Spanning Four Countries
Siemens CVSS 10.0 Flaw, Rockwell PLC DoS Patched in ICS Tuesday
VMware Avi Load Balancer Patches Critical Control Plane Auth Bypass
Jalisco and OmegaLord PhaaS Kits Beat M365 MFA Using OAuth Tricks
White House Launches Gold Eagle AI Vulnerability Routing Program
Cybersecurity
Forg365 PhaaS Combines AiTM and Device Code Flow to Target M365
Forg365 is a new phishing-as-a-service platform combining AiTM session hijacking and Device Code Flow abuse with AI-generated lures for mass targeting.
Cybersecurity
200 GitHub Repos Used as Dead Drop C2 Network for Windows Malware
Researchers exposed a network of 200 GitHub repositories serving as C2 dead drops for Windows malware, delivered via a malicious Go module and PowerShell chain.
CVE Vulnerability Alerts
Palo Alto Networks Patches 13 PAN-OS Flaws Including Auth Bypass
Palo Alto Networks patched 13 PAN-OS vulnerabilities including buffer overflow, command injection, SSRF, and authentication bypass in its firewall platform.
Cybersecurity
NHS Forth Valley Employee Emails Maternity Data to Personal Account
NHS Forth Valley disclosed a breach after a staff member emailed maternity patient data, including NHS numbers and pregnancy records, to a personal account.
Cybersecurity
EU Parliament Falls Short of Votes to Block Chat Control Return
European Parliament voted 314-276 against EU Chat Control but fell short of the 360-seat absolute majority needed to block the message scanning law's return.
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
Application Security
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.
CVE Vulnerability Alerts
Seven FatFs Flaws Threaten Cameras, Drones, and Crypto Wallets
runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem library affecting hundreds of millions of IoT devices, drones, and hardware wallets.
Cybersecurity
Microsoft Warns AI Tools Will Accelerate Windows Patch Volumes
Microsoft warned enterprises that its AI-assisted vulnerability discovery tools will produce higher Windows patch volumes and more frequent out-of-band updates.
IPNetwork Monitor Adds Native PostgreSQL Monitoring and One-Click Zabbix Import to Its Self-Hosted Platform
Cybersecurity
IPNetwork Monitor Adds Native PostgreSQL Monitoring and One-Click Zabbix Import to Its Self-Hosted Platform
IPNetwork Monitor LLC has released a major update to its self-hosted network and server monitoring platform, adding native PostgreSQL database ...
Application Security
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two Joomla extensions by July 10.
CVE Vulnerability Alerts
Ubiquiti Patches Seven Critical UniFi OS Flaws, 100K at Risk
Ubiquiti patched seven critical-to-maximum severity flaws in UniFi OS, led by CVE-2026-50746, a command injection requiring only network access to exploit.
Cybersecurity
Accenture Confirms Breach After Hacker Lists 35 GB for Sale
Threat actor '888' listed 35 GB of Accenture source code, RSA keys, SSH keys, and Azure access tokens for sale on a criminal forum in ...
Cybersecurity
Cisco Talos Exposes UAT-7810 LONGLEASH Backdoor on Ruckus Routers
Cisco Talos disclosed UAT-7810, a China-linked APT building the LapDogs ORB relay network using LONGLEASH malware on compromised Ruckus and ASUS routers.
Cybersecurity
UK NCSC Publishes Cyber Shield Blueprint for AI Defense
The UK NCSC published its Cyber Shield blueprint on July 7, outlining autonomous AI agents to discover and remediate vulnerabilities across government networks.
BonkDAO Loses $20M After Attacker Buys Quorum with ~$4M
Application Security
BonkDAO Loses $20M After Attacker Buys Quorum with ~$4M
An attacker spent approximately $4 million on BONK tokens to control 99.9% of votes in a low-turnout ballot and drain $20 million from BonkDAO's Solana ...
Cybersecurity
Eight Predatorgate Victims Sue Intellexa for €8 Million
Eight victims of the Greek Predatorgate spyware scandal filed a €8 million civil lawsuit against Intellexa and founder Tal Dilian in a Greek court on ...
CVE Vulnerability Alerts
CVE-2026-53359 Januscape: 16-Year KVM Flaw Enables VM Escape
CVE-2026-53359 Januscape is a 16-year-old Linux KVM use-after-free that allows guest VM escape to the host on Intel and AMD systems. Patches are available.
Cybersecurity
Operation DragonReturn: DcRAT Targets India Tax Professionals
China-nexus Operation DragonReturn deploys DcRAT via a cloned Indian tax utility, targeting tax professionals and accountants during India's filing season.
Cybersecurity
UK Cyber Resilience Pledge Draws 60 Signatories, Including Capita
UK Technology Secretary Liz Kendall launched the Cyber Resilience Pledge with 60 signatories, including Capita, despite its ICO fine for a ransomware breach.
Cybersecurity
CSE Admits Hacking Ransomware Gangs and Deleting Stolen Victim Data
Canada's CSE confirmed offensive cyber operations against ransomware gangs, including destroying a gang's full infrastructure and deleting stolen victim data.

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
NHS Forth Valley Employee Emails Maternity Data to Personal Account
NHS Forth Valley disclosed a breach after a staff member emailed maternity patient data, including NHS numbers and pregnancy records, to a personal account.
EU Parliament Falls Short of Votes to Block Chat Control Return
European Parliament voted 314-276 against EU Chat Control but fell short of the 360-seat absolute majority needed to block the message scanning law's return.
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.
Seven FatFs Flaws Threaten Cameras, Drones, and Crypto Wallets
runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem library affecting hundreds of millions of IoT devices, drones, and hardware wallets.
Microsoft Warns AI Tools Will Accelerate Windows Patch Volumes
Microsoft warned enterprises that its AI-assisted vulnerability discovery tools will produce higher Windows patch volumes and more frequent out-of-band updates.
IPNetwork Monitor Adds Native PostgreSQL Monitoring and One-Click Zabbix Import to Its Self-Hosted Platform
IPNetwork Monitor LLC has released a major update to its self-hosted network and server monitoring platform, adding native PostgreSQL database monitoring, a simplified way to ...
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two Joomla extensions by July 10.
Ubiquiti Patches Seven Critical UniFi OS Flaws, 100K at Risk
Ubiquiti patched seven critical-to-maximum severity flaws in UniFi OS, led by CVE-2026-50746, a command injection requiring only network access to exploit.
Accenture Confirms Breach After Hacker Lists 35 GB for Sale
Threat actor '888' listed 35 GB of Accenture source code, RSA keys, SSH keys, and Azure access tokens for sale on a criminal forum in ...
Cisco Talos Exposes UAT-7810 LONGLEASH Backdoor on Ruckus Routers
Cisco Talos disclosed UAT-7810, a China-linked APT building the LapDogs ORB relay network using LONGLEASH malware on compromised Ruckus and ASUS routers.
UK NCSC Publishes Cyber Shield Blueprint for AI Defense
The UK NCSC published its Cyber Shield blueprint on July 7, outlining autonomous AI agents to discover and remediate vulnerabilities across government networks.
BonkDAO Loses $20M After Attacker Buys Quorum with ~$4M
An attacker spent approximately $4 million on BONK tokens to control 99.9% of votes in a low-turnout ballot and drain $20 million from BonkDAO's Solana ...
Eight Predatorgate Victims Sue Intellexa for €8 Million
Eight victims of the Greek Predatorgate spyware scandal filed a €8 million civil lawsuit against Intellexa and founder Tal Dilian in a Greek court on ...
CVE-2026-53359 Januscape: 16-Year KVM Flaw Enables VM Escape
CVE-2026-53359 Januscape is a 16-year-old Linux KVM use-after-free that allows guest VM escape to the host on Intel and AMD systems. Patches are available.
Operation DragonReturn: DcRAT Targets India Tax Professionals
China-nexus Operation DragonReturn deploys DcRAT via a cloned Indian tax utility, targeting tax professionals and accountants during India's filing season.
UK Cyber Resilience Pledge Draws 60 Signatories, Including Capita
UK Technology Secretary Liz Kendall launched the Cyber Resilience Pledge with 60 signatories, including Capita, despite its ICO fine for a ransomware breach.
CSE Admits Hacking Ransomware Gangs and Deleting Stolen Victim Data
Canada's CSE confirmed offensive cyber operations against ransomware gangs, including destroying a gang's full infrastructure and deleting stolen victim data.
GitLost Prompt Injection Leaks Private GitHub Repos via Public Issues
Noma Security's GitLost technique tricks GitHub Agentic Workflows into leaking private repository contents via public issue comments, with no patch available.
WriteOut Flaw Let Attackers Hijack Any Writer AI Enterprise Account
Sand Security found a one-click session isolation flaw in Writer AI letting attackers access any enterprise tenant's private models, credentials, and documents.
Japan Arrests Teen Who Used ChatGPT to Cancel 46,812 Bandai Accounts
Tokyo police arrested a 15-year-old who used ChatGPT to generate attack code that canceled 46,812 Bandai Channel streaming accounts in under four hours.