Cyber Security
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Liechtenstein Register Breach Exposes Data of 31,000 People
UKGI Left Officials’ Contact Details Exposed for 40 Hours
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
South Korea Fines KT $39 Million Over 11-Month Breach
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware
Analog Devices Discloses Breach as ExfilSquad Claims Link
Copilot for Word Copy-Paste Attack Still Exploitable
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Cybersecurity
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
Coca-Cola filed an SEC Form 8-K disclosing a ransomware attack on Fairlife dairy that suspended all U.S. production. No group has yet claimed the attack.
Application Security
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA added SharePoint CVE-2026-58644, a CVSS 9.8 deserialization flaw, to KEV after Microsoft confirmed zero-day exploitation. Federal deadline is July 19.
CVE Vulnerability Alerts
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
CISA added CVE-2026-25089 and CVE-2026-39808 in Fortinet FortiSandbox to KEV, ordering FCEB agencies to patch by July 19 amid confirmed active exploitation.
Cybersecurity
23andMe Pays $18M to 43 State AGs Over Genetic Data Breach
Coalition of 43 state AGs reaches $18M settlement with 23andMe successor Chrome Holding Co. over its genetic data breach; total penalties exceed $50 million.
Cybersecurity
Italy Fines WINDTRE €1.7M for Breaches Exposing 365K Customers
Italy's Garante fined telecom operator WINDTRE €1.7 million for two 2024 data breaches in which social engineering attacks exposed data on 365,000 customers.
Cybersecurity
Interlock Hits DC Housing Authority; Play, Nova Post New Victims
Interlock ransomware targeted DC's public housing agency; Play posted five victims across four countries; Nova added three more in a multi-group batch.
Cybersecurity
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Application Security
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Zoom patched CVE-2026-53412, a CVSS 9.8 flaw in Zoom Workplace for Windows allowing unauthenticated remote account takeover with no user interaction required.
Application Security
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
Application Security
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.
Cybersecurity
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.
Cybersecurity
PhantomEnigma Weaponizes 20+ Brazilian Gov Sites for Malware Delivery
ANY.RUN disclosed PhantomEnigma, a campaign that hijacked 20-plus Brazilian gov.br domains to distribute malware via police-themed phishing emails that pass SPF, DKIM, and DMARC.
Cybersecurity
Chinese Actors Weaponized Claude Code in Multi-Nation Espionage Op
Hunt.io exposed a Chinese state-linked espionage operation that used Claude Code and DeepSeek as direct attack tools, breaching systems in four countries.
CVE Vulnerability Alerts
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring no authentication to exploit.
Cybersecurity
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and AI-generated code.
Cybersecurity
CoinbaseCartel Hits Panasonic Avionics; Pear Targets US Healthcare
CoinbaseCartel claimed Panasonic Avionics, Pear ransomware hit two US healthcare providers, and six groups posted victims across multiple sectors and countries.
CVE Vulnerability Alerts
SonicWall SMA1000 CVSS 10.0 Zero-Day Hits Remote Access Gateways
SonicWall warns of active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SMA1000 appliances. Federal agencies must patch by July 17.
Application Security
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
CISA added three SharePoint CVEs to its KEV catalog after confirming active attack chains combining auth bypass, code execution, and IIS machine key theft.
Cybersecurity
DOJ Charges Three Russians Behind LockBit, Play Hosting Network
The DOJ unsealed charges against three Russians who ran Media Land and ML.Cloud, bulletproof hosting that served LockBit, Blacksuit, and Play ransomware.
Application Security
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
Progress confirmed a path traversal zero-day in ShareFile SZC 5.x and 6.x after ordering an emergency shutdown. Patches 5.12.5 and 6.0.2 are now available.

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
23andMe Pays $18M to 43 State AGs Over Genetic Data Breach
Coalition of 43 state AGs reaches $18M settlement with 23andMe successor Chrome Holding Co. over its genetic data breach; total penalties exceed $50 million.
Italy Fines WINDTRE €1.7M for Breaches Exposing 365K Customers
Italy's Garante fined telecom operator WINDTRE €1.7 million for two 2024 data breaches in which social engineering attacks exposed data on 365,000 customers.
Interlock Hits DC Housing Authority; Play, Nova Post New Victims
Interlock ransomware targeted DC's public housing agency; Play posted five victims across four countries; Nova added three more in a multi-group batch.
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Zoom patched CVE-2026-53412, a CVSS 9.8 flaw in Zoom Workplace for Windows allowing unauthenticated remote account takeover with no user interaction required.
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.
PhantomEnigma Weaponizes 20+ Brazilian Gov Sites for Malware Delivery
ANY.RUN disclosed PhantomEnigma, a campaign that hijacked 20-plus Brazilian gov.br domains to distribute malware via police-themed phishing emails that pass SPF, DKIM, and DMARC.
Chinese Actors Weaponized Claude Code in Multi-Nation Espionage Op
Hunt.io exposed a Chinese state-linked espionage operation that used Claude Code and DeepSeek as direct attack tools, breaching systems in four countries.
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring no authentication to exploit.
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and AI-generated code.
CoinbaseCartel Hits Panasonic Avionics; Pear Targets US Healthcare
CoinbaseCartel claimed Panasonic Avionics, Pear ransomware hit two US healthcare providers, and six groups posted victims across multiple sectors and countries.
SonicWall SMA1000 CVSS 10.0 Zero-Day Hits Remote Access Gateways
SonicWall warns of active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SMA1000 appliances. Federal agencies must patch by July 17.
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
CISA added three SharePoint CVEs to its KEV catalog after confirming active attack chains combining auth bypass, code execution, and IIS machine key theft.
DOJ Charges Three Russians Behind LockBit, Play Hosting Network
The DOJ unsealed charges against three Russians who ran Media Land and ML.Cloud, bulletproof hosting that served LockBit, Blacksuit, and Play ransomware.
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
Progress confirmed a path traversal zero-day in ShareFile SZC 5.x and 6.x after ordering an emergency shutdown. Patches 5.12.5 and 6.0.2 are now available.
300 Fake GitHub Repos Deliver BoryptGrab Chrome Bypass Infostealer
ArcticWolf exposed a campaign using 300 fake GitHub repos to deliver BoryptGrab, an infostealer that bypasses Chrome App-Bound Encryption via code injection.
Unpatched Claude for Chrome Flaw Exposes Gmail and Calendar Data
Manifold disclosed two unpatched flaws in Claude for Chrome allowing malicious extensions to invoke the AI agent and silently access Gmail and Google Calendar.
AsyncAPI npm Packages Backdoored to Deploy Miasma Botnet Loader
Four official AsyncAPI npm packages were compromised to deliver Miasma, a botnet loader using six C2 channels including Ethereum smart contracts and IPFS.