🐛 COMMON VULNERABILITIES AND EXPOSURES 59[−]
21 Jul KEVWhite hat hacker Park Chan-am zeros in on the AI era’s key security challengesDubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government agencie…CSOONLINE.COM
21 JulAttackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the Se…SECURITYAFFAIRS.COM
21 JulCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThreat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbo…THEHACKERNEWS.COM
21 JulCVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cacheInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iteratingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0'Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64077 netfilter: ebtables: move to two-stage removal schemeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pagesInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attrInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64017 blk-mq: pop cached request if it is usableInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64146 erofs: fix metabuf leak in inode xattr initializationInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon deviceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() accessInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64079 netfilter: x_tables: allocate hook ops while under mutexInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_pointInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritanceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNTInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64070 powerpc/hv-gpci: fix preempt count leak in sysfs show pathsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64015 security/keys: fix missed RCU read section on lookupInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63958 usb: typec: ucsi: validate connector number in ucsi_connector_change()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64117 wifi: mac80211: capture fast-RX rate before mesh reuses skb->cbInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap failsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64078 netfilter: x_tables: add and use xtables_unregister_table_exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63983 net/sched: fix packet loop on netem when duplicate is onInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record headerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63881 drm/amdkfd: fix a vulnerability of integer overflow in kfd debuggerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDOInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63963 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlersInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64154 drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmapInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64076 netfilter: bridge: eb_tables: close module init raceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handlingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failureInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63978 net/handshake: Drain pending requests at net namespace exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied qInformation published.MSRC.MICROSOFT.COM
21 JulWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningAttackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have be…THEHACKERNEWS.COM
21 JulExploitation of ServiceNow Vulnerability Seen Days After DisclosureThe ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSonicWall SMA zero-days were exploited weeks before disclosureTwo recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions b…HELPNETSECURITY.COM
21 JulQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessThreat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with…THEHACKERNEWS.COM
21 JulCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Of…THEHACKERNEWS.COM
21 JulCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulVU#762226: Plane contains multi-tenant authorization bypass vulnerabilityOverview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane …KB.CERT.ORG
21 JulCritical wp2shell WordPress flaws exploited to install webshellsHackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]BLEEPINGCOMPUTER.COM
21 JulQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN AccessQilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corpo…SECURITYAFFAIRS.COM
21 JulCritical SharePoint RCE flaw exploited to steal machine keysHackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]BLEEPINGCOMPUTER.COM
21 Jul KEVPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public p…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 37[−]
21 JulAI-generated reports push GNOME to shorten its disclosure windowVolunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and…HELPNETSECURITY.COM
21 Jul177: National Public DataThis is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show com…DARKNETDIARIES.COM
21 JulContext bombing heralds a new AI era of deceptive defenseAttackers are increasingly using AI agents to automate all phases of cyberattacks , prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the content…CSOONLINE.COM
21 JulNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackResearchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weig…THEHACKERNEWS.COM
21 JulWindows LegacyHive zero-day flaw gets free, unofficial patchesFree unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
21 JulWeekly Update 513: Clauding The Home NetworkPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?. I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - i…TROYHUNT.COM
21 JulEstée Lauder discloses data breach tied to Oracle EBS vulnerabilityCosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, frag…HELPNETSECURITY.COM
21 JulOpen-source maintainers still work underfunded as sponsorship crosses $100 millionA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and …HELPNETSECURITY.COM
21 JulUS Hospital Finance Software Provider Craneware Reports Data TheftCraneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theftINFOSECURITY-MAGAZINE.COM
21 JulThe Triumphs and Failures of France's Foreign Intel ServiceThe DGSE, or Directorate General for External Security, is France's foreign intelligence service. It's found inside the Ministry of Defense but reports to the president. It was established under that name in 1982, learning the hard way, through a string of high-profile blunders, …THECYBERWIRE.COM
21 JulCritical Palo Alto VPN bug now exploited by Qilin ransomware gangThe Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]BLEEPINGCOMPUTER.COM
21 JulMeta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataA security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulAI agents can escape sandboxes without ever breaking themSandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and …CSOONLINE.COM
21 JulEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackHackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsAn Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated tha…THEHACKERNEWS.COM
21 JulN-day is Becoming N-Hour. Patching Faster Won't Save You.Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is…THEHACKERNEWS.COM
21 JulNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitA cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper acce…THEHACKERNEWS.COM
21 JulYour AI agent’s config is now the payload: How attackers are targeting the developer agent harnessAttackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' o…TENABLE.COM
21 JulCisco’s open-weight Antares models make vulnerability localization cheaperA security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands of files. That fi…HELPNETSECURITY.COM
21 JulPersonal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattackSeo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intellig…DATABREACHES.NET
21 JulNYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from InvestigatorsOne of the biggest breaches of 2016 was the Panama Papers leak. The law firm at the heart of it, Mossack Fonseca, closed its doors in 2018, unable to recover from all the damage. But while the law firm folded, investigations continued. The New York Department of Financial Service…DATABREACHES.NET
21 JulSuno Data Breach had a breach in 2025. Why is it first being known now?Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered …DATABREACHES.NET
21 JulSeoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free PassesKim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and …DATABREACHES.NET
21 JulTaiwan to slow mobile data during national resilience drillsThe speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.THERECORD.MEDIA
21 JulZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesZimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a …THEHACKERNEWS.COM
21 JulMacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's a…YOUTUBE.COM
21 JulAI agents tricked into recommending malicious GitHub repositoriesRoughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are t…HELPNETSECURITY.COM
21 JulWhat happens if you visit a WordPress site hacked through wp2shell?Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.MALWAREBYTES.COM
21 JulAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeHidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary a…THEHACKERNEWS.COM
21 JulMicrosoft SharePoint under attack via new exploitSecurity researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.CYBERSECURITYDIVE.COM
21 JulCisco Launches Low-Cost AI Models for Source Code SecurityThe open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulZimbra 10.1.20 patches multiple security issues, including a critical command injection bugZimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitorin…SECURITYAFFAIRS.COM
21 JulCyberattack against Maine telecom disrupted municipal internet service in 23 townsColin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along the state’s midcoastal region. A local NBC affiliate reported…DATABREACHES.NET
21 JulLegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More. Segment Resources: Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-…YOUTUBE.COM
21 JulOracle July 2026 Critical Patch Update Addresses 1235 CVEsOracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% …TENABLE.COM
21 JulOpenAI Models Escaped Containment and Hacked HuggingFaceThe cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.WIRED.COM
21 JulPay up or not? Ransomware surge has victims facing tough choices.Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdicti…DATABREACHES.NET
📢 SECURITY ADVISORIES 10[−]
21 JulMicrosoft shares manual fix for WSUS sync delays and timeoutsMicrosoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]BLEEPINGCOMPUTER.COM
21 JulShufti simplifies cross-border compliance with the Glocal PlatformShufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and …HELPNETSECURITY.COM
21 JulThe Trump administration's AI czar resigns.Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.THECYBERWIRE.COM
21 JulHouse intel bill includes provisions on state and local threat intelligence, election security, AIThe House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop .CYBERSCOOP.COM
21 JulWhere’s the Trump administration line on AI regulation?The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts said. The post Where’s the Trump administration line on AI regulation? appeared first on CyberScoop .CYBERSCOOP.COM
21 JulTrump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply ChainsNew executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first o…SECURITYWEEK.COM
🔥 INCIDENT REPORTING 18[−]
21 JulPR3TACK preemptive framework maps threats before attackers use themDefensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn t…HELPNETSECURITY.COM
21 JulThe air gap is a myth and other OT security truthsBenjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containme…HELPNETSECURITY.COM
21 JulData breach at AI music service Suno exposed 55 million accountsAI music generation platform Suno suffered a data breach that exposed the personal information of more than 55 million users, according to Have I Been Pwned (HIBP). The incident exposed phone numbers and tens of thousands of Stripe purchase records containing customer names, phys…CYBERINSIDER.COM
21 JulUkraine warns fake CAPTCHAs are being used to make you hack yourselfUkraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
21 JulA Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It NowDealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.WIRED.COM
21 JulClover Health Investments Discloses Data BreachUsing social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationPart of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulKenya probes hack of president's website after bitcoin ransom demandThe website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.THERECORD.MEDIA
21 JulA New Ransomware Threat Actor Emerges Every Week, Warns ReportAnalysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmentedINFOSECURITY-MAGAZINE.COM
21 JulClosing the Identity Gaps in Critical Infrastructure SecurityCritical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]BLEEPINGCOMPUTER.COM
21 JulJadePuffer returns with ransomware built to target AI models and infrastructureJadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransom…HELPNETSECURITY.COM
21 JulAI music generator Suno breach affects 55M users, per Have I Been PwnedA hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.TECHCRUNCH.COM
21 JulRansomware victims fail to fix flaws that exposed themMany organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.CYBERSECURITYDIVE.COM
21 JulSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackThe Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.THERECORD.MEDIA
21 JulAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakThe Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]BLEEPINGCOMPUTER.COM
21 JulThe defense against the AI arts.Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and c…THECYBERWIRE.COM
21 JulRansomware Is Accelerating, But It's Not Because of AIResearchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.DARKREADING.COM
21 JulOpenAI says model test was behind Hugging Face hackAt the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop .CYBERSCOOP.COM
🕵️ THREAT INTELLIGENCE 26[−]
21 JulISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 JulCybersecurity jobs available right now: July 21, 2026Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation effo…HELPNETSECURITY.COM
21 JulAI agents are still logging in as humansMost large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep…HELPNETSECURITY.COM
21 JulNobody was checking the drives that encrypt your laptopA drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought…HELPNETSECURITY.COM
21 JulZimbra Update Patches Critical VulnerabilitiesThe latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulWhat the World Cup can teach us about cybersecurity resilienceFuture major events can’t rely on yesterday's playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters. The post What the World Cup can teach us about cybersecurity resilience appeared first on Cybe…CYBERSCOOP.COM
21 JulResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 ProsIn a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojansINFOSECURITY-MAGAZINE.COM
21 JulAWS wants GuardDuty to automate the first steps of threat investigationsAmazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is availab…HELPNETSECURITY.COM
21 JulFake FBI agents target people who already got scammedScammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from Apr…HELPNETSECURITY.COM
21 JulMIT to Become Hotbed of AI Video SurveillanceIt’s a lot : According to information obtained by The Tech , MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and i…SCHNEIER.COM
21 JulCISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AGGaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulA new extortion cocktail: office printers, small ransoms, and BitLockerWe cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.SECURELIST.COM
21 JulEmpirical Security Raises $25 Million in Series A FundingThe startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial CybersecurityIndependently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launc…SECURITYWEEK.COM
21 JulLoop engineering comes to the SOC: Introducing the Intezer Org BrainOrganizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously. The post Loop engineering comes to the SOC: Introducing the Intezer Org Brain …INTEZER.COM
21 JulCaptive Portal Detection, (Tue, Jul 21st)Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" list currently includes "http://detectportal.firefox.co
m/success.txt" as one of the new URLs detected by our honeypots. The hostname "detectporta…ISC.SANS.EDU
21 JulRussian Hacker Turns Jailbroken Claude Into Pentest PlatformRussian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude modelsINFOSECURITY-MAGAZINE.COM
21 JulDruva brings backup, recovery and governance to AI workloadsDruva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Prot…HELPNETSECURITY.COM
21 JulArgon2 algorithm dramatically slows password cracking by high-end GPUsA new study shows that the Argon2id password hashing algorithm dramatically increases the cost of offline password cracking by neutralizing much of the advantage offered by modern GPUs. The study by Specops researcher David Ketler examines how Argon2id performs against modern pas…CYBERINSIDER.COM
21 JulTeleport enhances Identity Security platform with new AI agent behavior controlsTeleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying …HELPNETSECURITY.COM
21 JulNorth Korea’s IT worker scheme funds Russia’s war effortDTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. The post North Korea’s IT worker scheme funds Russia’s war effort appeared first o…CYBERSCOOP.COM
21 JulIgnore Apple, Pay the PricePatrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible. Choosing unsupported techniques may seem like the better engineering decision at first, but platform changes often…YOUTUBE.COM
21 JulFirefox 153 adds built-in Containers for easy account isolationMozilla has released Firefox 153, introducing built-in Containers as a native browser feature alongside HDR video playback on Windows, new PDF editing capabilities, and several security improvements. Firefox 153 is now rolling out to users on the browser's Release channel. The up…CYBERINSIDER.COM
21 JulDon't Overbuild Your AI WorkflowLarge codebases don't fit into a single LLM prompt. As projects grow, developers often need to split work into smaller pieces and guide the model with structured workflows. That doesn't mean you should build an elaborate AI harness from day one. A simple workflow often delivers t…YOUTUBE.COM
21 JulAI models keep getting caught cheatingNew research from the UK shows how nearly every model tested tried to cheat, scam or cut corners on its way to solving problems. The post AI models keep getting caught cheating appeared first on CyberScoop .CYBERSCOOP.COM
21 JulEvery Browser Extension Is a TradeoffNot all browser extensions present the same level of risk. Security teams evaluate whether an extension supports a legitimate business need and what permissions it requests before deciding whether to allow it. An extension that enables essential work may be acceptable when paired…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
21 Jul KEVSecuring Research Infrastructure and Managing Shadow AI with Kevin MortimerHost Caleb Tolin sits down with Kevin Mortimer to discuss securing higher education infrastructure and managing the shift toward autonomous AI deployment. Kevin details his experience supporting research environments, expanding multi factor authentication controls, and defending …THECYBERWIRE.COM
21 JulIran War Cyber Threat Landscape | A Midyear Assessment on What MattersIn April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.SENTINELONE.COM
21 JulNew ClickLock Stealer locks your Mac until you hand over your passwordA new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access.MALWAREBYTES.COM
21 JulA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind SpotsA new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users.WIRED.COM
21 JulFakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareA large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
21 JulBetween Two Nerds: What China gets wrong about Russia's cyber war in UkraineIn this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine. This episode is also available on YouTube.RISKY.BIZ
📡 INFOSEC NEWS 15[−]
21 JulNew Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoveryKaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.SECURELIST.COM
21 JulAI nudify apps spark legal scrutiny of Apple and Google’s profitsInstead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps.MALWAREBYTES.COM
21 JulDon’t trust that “FBI agent” in your DMsThe FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.MALWAREBYTES.COM
21 JulFBI Warns of Deepfake Videos Impersonating IC3 LeadershipFBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sitesINFOSECURITY-MAGAZINE.COM
21 JulUS seizes over 1,000 websites in FIFA World Cup piracy crackdownThe U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]BLEEPINGCOMPUTER.COM
21 JulChoose Wisely: AI-Generated Coding Risk Varies, A LotAI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.DARKREADING.COM
21 Jul300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AIAs AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.WIZ.IO
21 JulAgentless Visibility: Uncovering Cloud Blind SpotsHow Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.WIZ.IO
21 JulGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesGoogle's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model wil…THEHACKERNEWS.COM
21 JulDo more with AWS WAF labels using dynamic label interpolationAWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from …AWS.AMAZON.COM
21 JulHacker Turns AI Jailbreaks Into Offensive Attack PlatformA Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.DARKREADING.COM
21 JulDNI nominee Clayton wins Senate panel’s approvalBy a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor.THERECORD.MEDIA
21 JulUsing LLMs to Find and Prioritize Vulnerabilities Is No Easy TaskThe latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.DARKREADING.COM
21 JulPolice dismantle Kratos phishing platform, arrest developerAuthorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]BLEEPINGCOMPUTER.COM