Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Cybersecurity
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Application Security
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Zoom patched CVE-2026-53412, a CVSS 9.8 flaw in Zoom Workplace for Windows allowing unauthenticated remote account takeover with no user interaction required.
Application Security
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
Application Security
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.
Cybersecurity
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.
Cybersecurity
PhantomEnigma Weaponizes 20+ Brazilian Gov Sites for Malware Delivery
ANY.RUN disclosed PhantomEnigma, a campaign that hijacked 20-plus Brazilian gov.br domains to distribute malware via police-themed phishing emails that pass SPF, DKIM, and DMARC.
Cybersecurity
Chinese Actors Weaponized Claude Code in Multi-Nation Espionage Op
Hunt.io exposed a Chinese state-linked espionage operation that used Claude Code and DeepSeek as direct attack tools, breaching systems in four countries.
CVE Vulnerability Alerts
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring no authentication to exploit.
Cybersecurity
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and AI-generated code.
Cybersecurity
CoinbaseCartel Hits Panasonic Avionics; Pear Targets US Healthcare
CoinbaseCartel claimed Panasonic Avionics, Pear ransomware hit two US healthcare providers, and six groups posted victims across multiple sectors and countries.
CVE Vulnerability Alerts
SonicWall SMA1000 CVSS 10.0 Zero-Day Hits Remote Access Gateways
SonicWall warns of active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SMA1000 appliances. Federal agencies must patch by July 17.
Application Security
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
CISA added three SharePoint CVEs to its KEV catalog after confirming active attack chains combining auth bypass, code execution, and IIS machine key theft.
Cybersecurity
DOJ Charges Three Russians Behind LockBit, Play Hosting Network
The DOJ unsealed charges against three Russians who ran Media Land and ML.Cloud, bulletproof hosting that served LockBit, Blacksuit, and Play ransomware.
Application Security
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
Progress confirmed a path traversal zero-day in ShareFile SZC 5.x and 6.x after ordering an emergency shutdown. Patches 5.12.5 and 6.0.2 are now available.
Cybersecurity
300 Fake GitHub Repos Deliver BoryptGrab Chrome Bypass Infostealer
ArcticWolf exposed a campaign using 300 fake GitHub repos to deliver BoryptGrab, an infostealer that bypasses Chrome App-Bound Encryption via code injection.
Application Security
Unpatched Claude for Chrome Flaw Exposes Gmail and Calendar Data
Manifold disclosed two unpatched flaws in Claude for Chrome allowing malicious extensions to invoke the AI agent and silently access Gmail and Google Calendar.
Application Security
AsyncAPI npm Packages Backdoored to Deploy Miasma Botnet Loader
Four official AsyncAPI npm packages were compromised to deliver Miasma, a botnet loader using six C2 channels including Ethereum smart contracts and IPFS.
Cybersecurity
Spanish Police Break Up €140M BEC Ring Spanning Four Countries
Spanish National Police and Europol dismantled a €140 million BEC and investment fraud ring, arresting four suspects across Spain, Portugal, and Panama.
CVE Vulnerability Alerts
Siemens CVSS 10.0 Flaw, Rockwell PLC DoS Patched in ICS Tuesday
Siemens, Rockwell, and Schneider Electric issued ICS Patch Tuesday advisories, including a CVSS 10.0 Opencenter X auth bypass and CompactLogix DoS flaws.
CVE Vulnerability Alerts
VMware Avi Load Balancer Patches Critical Control Plane Auth Bypass
Broadcom patched seven VMware Avi vulnerabilities, including a critical authentication bypass in the control plane. No active exploitation has been confirmed.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.
Bitdefender Exposes Windows Bind Link Attacks That Bypass EDR Tools
Bitdefender documented three Windows bind link techniques — file-binding, process-binding, and silo-binding — that redirect OS path resolution to hide malware from EDR tools.
PhantomEnigma Weaponizes 20+ Brazilian Gov Sites for Malware Delivery
ANY.RUN disclosed PhantomEnigma, a campaign that hijacked 20-plus Brazilian gov.br domains to distribute malware via police-themed phishing emails that pass SPF, DKIM, and DMARC.
Chinese Actors Weaponized Claude Code in Multi-Nation Espionage Op
Hunt.io exposed a Chinese state-linked espionage operation that used Claude Code and DeepSeek as direct attack tools, breaching systems in four countries.
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring no authentication to exploit.
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and AI-generated code.
CoinbaseCartel Hits Panasonic Avionics; Pear Targets US Healthcare
CoinbaseCartel claimed Panasonic Avionics, Pear ransomware hit two US healthcare providers, and six groups posted victims across multiple sectors and countries.
SonicWall SMA1000 CVSS 10.0 Zero-Day Hits Remote Access Gateways
SonicWall warns of active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SMA1000 appliances. Federal agencies must patch by July 17.
CISA Adds Three SharePoint CVEs to KEV as Auth-to-RCE Chain
CISA added three SharePoint CVEs to its KEV catalog after confirming active attack chains combining auth bypass, code execution, and IIS machine key theft.
DOJ Charges Three Russians Behind LockBit, Play Hosting Network
The DOJ unsealed charges against three Russians who ran Media Land and ML.Cloud, bulletproof hosting that served LockBit, Blacksuit, and Play ransomware.
Progress ShareFile Path Traversal Zero-Day Confirmed, Patches Out
Progress confirmed a path traversal zero-day in ShareFile SZC 5.x and 6.x after ordering an emergency shutdown. Patches 5.12.5 and 6.0.2 are now available.
300 Fake GitHub Repos Deliver BoryptGrab Chrome Bypass Infostealer
ArcticWolf exposed a campaign using 300 fake GitHub repos to deliver BoryptGrab, an infostealer that bypasses Chrome App-Bound Encryption via code injection.
Unpatched Claude for Chrome Flaw Exposes Gmail and Calendar Data
Manifold disclosed two unpatched flaws in Claude for Chrome allowing malicious extensions to invoke the AI agent and silently access Gmail and Google Calendar.
AsyncAPI npm Packages Backdoored to Deploy Miasma Botnet Loader
Four official AsyncAPI npm packages were compromised to deliver Miasma, a botnet loader using six C2 channels including Ethereum smart contracts and IPFS.
Spanish Police Break Up €140M BEC Ring Spanning Four Countries
Spanish National Police and Europol dismantled a €140 million BEC and investment fraud ring, arresting four suspects across Spain, Portugal, and Panama.
Siemens CVSS 10.0 Flaw, Rockwell PLC DoS Patched in ICS Tuesday
Siemens, Rockwell, and Schneider Electric issued ICS Patch Tuesday advisories, including a CVSS 10.0 Opencenter X auth bypass and CompactLogix DoS flaws.
VMware Avi Load Balancer Patches Critical Control Plane Auth Bypass
Broadcom patched seven VMware Avi vulnerabilities, including a critical authentication bypass in the control plane. No active exploitation has been confirmed.
Jalisco and OmegaLord PhaaS Kits Beat M365 MFA Using OAuth Tricks
ReliaQuest disclosed Jalisco, which regenerates OAuth tokens in real time to beat Microsoft's 15-minute window, and OmegaLord, which harvests MFA phone numbers.
White House Launches Gold Eagle AI Vulnerability Routing Program
White House launched Gold Eagle, linking CISA, open source maintainers, and critical infrastructure operators through AI vulnerability triage under EO 14409.
Nine-Nation Advisory Flags FSB Center 16 Router Attacks
Cybersecurity agencies from nine countries issued a joint advisory on FSB Center 16 router attacks targeting energy, healthcare, and defense sectors globally.