🚨 CISA KEV 1[−]
22 Jul KEVU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 28[−]
22 JulWordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto BugWP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs…CYBERSECURITYTODAY.LIBSYN.COM
22 JulCVE-2026-42533 NGINX Map directive and Regex matching vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-56434 NGINX ngx_http_ssi_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.cInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitializedInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resizeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()Information published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zeroInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64187 xfs: fail recovery on a committed log item with no regionsInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64205 i2c: i801: fix hardware state machine corruption in error pathInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode changeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lockInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid lengthInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-39879 SQL injection in syslog-ng SQL destionation driverInformation published.MSRC.MICROSOFT.COM
22 JulFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksCVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments follow…HELPNETSECURITY.COM
22 JulHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationA high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log…THEHACKERNEWS.COM
22 JulCVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulCVE-2026-50458 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulVU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerabilityOverview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Q…KB.CERT.ORG
22 JulWhat’s New in Rapid7 Products and Services: Q2 2026 in ReviewIf Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams redu…RAPID7.COM
22 JulAdobe fixes Chrome extension flaw that could expose WhatsApp chatsA chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim's WhatsApp Web session simply by luring them to a malicious website. Adobe fixed the flaws within days of the report and assigned the issue CVE-2026-48294.…CYBERINSIDER.COM
22 JulVU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerabilityOverview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placi…KB.CERT.ORG
22 JulUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsCybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933…THEHACKERNEWS.COM
22 JulOracle’s July update fixes ten 10.0 vulnerabilities in Fusion MiddlewareOracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new…CSOONLINE.COM
22 JulCritical Zimbra security update fixes 9 vulnerabilitiesBusiness email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collaboration S…CSOONLINE.COM
22 JulAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theftAdobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that a…SECURITYAFFAIRS.COM
22 JulCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protectionsQualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affect…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 45[−]
22 JulApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsApple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, af…THEHACKERNEWS.COM
22 JulMilford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected CyberattackMilford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email …DATABREACHES.NET
22 JulLG to Ban Residential Proxies from Smart TV AppsThe home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth…KREBSONSECURITY.COM
22 JulCloud operations become the next big role for agentic AICompanies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. T…HELPNETSECURITY.COM
22 JulSecurity teams keep finding critical flaws after scheduled testing endsEnterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critic…HELPNETSECURITY.COM
22 JulAI can’t fix cybersecurity’s hiring problemOrganizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doub…HELPNETSECURITY.COM
22 JulSnowpick: Open-source ServiceNow exposure scannerAn employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration…HELPNETSECURITY.COM
22 Jul10 survival tips for CSOs who report to the CEOAs the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and influence…CSOONLINE.COM
22 JulRisky Bulletin: Rogue OpenAI models were behind the Hugging Face breachRogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.RISKY.BIZ
22 JulPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFAGerman and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on …THEHACKERNEWS.COM
22 JulOpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceThe admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulPolice dismantle Kratos phishing platform behind 15,000 monthly campaignsGerman and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfur…HELPNETSECURITY.COM
22 JulAI, security operations and the new race against timeWhen Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers…CSOONLINE.COM
22 JulGoogle’s Gemini 3.5 Flash Cyber becomes a vulnerability hunterGoogle’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender,…HELPNETSECURITY.COM
22 JulEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationUsing AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI AI models exploited zero-days to reach Hugging Face in benchmark testOpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberatta…SECURITYAFFAIRS.COM
22 JulUbuntu snap-confine Vulnerability Enables Local Root AccessNew Ubuntu snap-confine race condition lets local users escalate to root on default installsINFOSECURITY-MAGAZINE.COM
22 JulGoogle Makes CodeMender Available as Managed AI Security AgentCodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitableINFOSECURITY-MAGAZINE.COM
22 JulChick-fil-A hit by credential stuffing attack exposing customer dataChick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential stuffing attack against the company's website and mobile application. The incident, which occurred in June, allowed unauthorized parties to view personal …CYBERINSIDER.COM
22 JulUS seizes over 1,000 domains used for illegal World Cup 2026 streamsThe US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rou…HELPNETSECURITY.COM
22 JulLookout identifies exploitable vulnerabilities in mobile appsLookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities acros…HELPNETSECURITY.COM
22 JulOpen AI Claims Its AI Models Went Rogue and Hacked Another CompanyHugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselvesINFOSECURITY-MAGAZINE.COM
22 Jul KEVCISA orders urgent action on actively exploited Langflow RCE flawThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
22 JulThe Fastest Path to AI Adoption Runs Through SecuritySecurity leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. A…THEHACKERNEWS.COM
22 JulOpenAI model escape puts enterprise AI defenses on noticeSome of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that producti…CSOONLINE.COM
22 JulVibe-Coded Apps Riddled With Exploitable Security FlawsAnalysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI Presence connects AI agents to enterprise data with built-in guardrailsOpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “…HELPNETSECURITY.COM
22 JulAstelia extends reachability analysis with agentic AI for vulnerability managementAstelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vul…HELPNETSECURITY.COM
22 JulInfraTrust Knowledgebase Unlocks Critical Hardware Risk IntelligenceToday we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated s…ECLYPSIUM.COM
22 JulAI Added a Third EmployeeAI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity. That changes the incentives for employers. If AI can reliably handle part of the workload, businesses may …YOUTUBE.COM
22 JulOpenAI: Our models breached Hugging Face during a cyber capability testThe recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal…HELPNETSECURITY.COM
22 JulThreat group claims credit for ransomware attack on Coca-Cola’s dairy unitThe attackers previously exploited vulnerabilities or used stolen credentials for initial access. CYBERSECURITYDIVE.COM
22 JulGreedy ransomware crews return for seconds after victims cough up first extortion paymentsConnor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. …DATABREACHES.NET
22 JulCisco’s new AI model tells code reviewers where to look for vulnerabilitiesCisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models se…CSOONLINE.COM
22 JulApple patches Hide My Email flaw after media reports and class-action lawsuitApple has fixed a vulnerability in its iCloud+ Hide My Email service that could expose users' real email addresses. The fix comes over a year after a security researcher privately reported the issue and only weeks after 404 Media publicly disclosed it. The company confirmed to 40…CYBERINSIDER.COM
22 JulThe AI has entered the chat.GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Orac…THECYBERWIRE.COM
22 JulSouth Korea discloses data breach impacting diplomats worldwideSouth Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]BLEEPINGCOMPUTER.COM
22 JulFake Bahrain Alert App Deploys Android Surveillance MalwareA malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.DARKREADING.COM
22 JulAre Schools Falling Behind AI?Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace. Waiting until workforce shortages appear could mean reacting t…YOUTUBE.COM
22 JulUpbound says hack caused $13 million in fraudulent Acima leasesThe Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]BLEEPINGCOMPUTER.COM
22 JulAttackers Are Learning to Live Off the AI ToolchainSandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.DARKREADING.COM
22 JulSmashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hackerA Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen …GRAHAMCLULEY.COM
22 JulGerman law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group KratosA global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. The effort was managed by German law enforcement…CSOONLINE.COM
22 JulOpenAI Models Escaped Containment and Hacked Hugging FaceIt’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open …DATABREACHES.NET
22 JulInstructure Incident Driving 58 Percent of Breach Notices in 2026GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices …DATABREACHES.NET
📋 SECURITY BULLETINS 3[−]
22 JulOracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesMany of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulMicrosoft to stop Exchange 2016 / 2019 security updates in OctoberMicrosoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. [...]BLEEPINGCOMPUTER.COM
22 JulEclypsium Launches InfraTrust to Centralize Enterprise Hardware Security RisksNew global infrastructure security intelligence database debuts alongside monthly advisory delivering actionable risk data to protect critical enterprise hardware infrastructure. Portland, OR – July 22, 2026 – Eclypsium, the infrastructure assurance company, today announced the l…ECLYPSIUM.COM
📢 SECURITY ADVISORIES 16[−]
22 JulStates Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking ThemFederal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work.WIRED.COM
22 JulEU Financial Institutions Leak Data Through Cookie TrackersEuropean banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.DARKREADING.COM
22 JulFederal agencies broaden alert on Iran-linked OT attacksThe observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.THERECORD.MEDIA
22 JulExtension of CISA 2015 info-sharing protections passes as part of House’s defense billA 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.THERECORD.MEDIA
22 JulMost federal cybersecurity reporting rules are duplicative, study findsThe Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 17[−]
22 JulRisky Business #845 -- OpenAI's Skynet momentOn this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries t…RISKY.BIZ
22 JulOpenAI says its AI models hacked Hugging Face during testingOpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]BLEEPINGCOMPUTER.COM
22 JulOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkOpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models w…THEHACKERNEWS.COM
22 JulChick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]BLEEPINGCOMPUTER.COM
22 JulProofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More EffectivePROOFPOINT.COM
22 JulRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeThe Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI confirms its AI agent autonomously breached Hugging FaceOpenAI has revealed that an autonomous AI agent powered by GPT-5.6 Sol and a more capable unreleased model escaped its intended testing environment, gained internet access, and compromised parts of Hugging Face's production infrastructure while attempting to obtain benchmark answ…CYBERINSIDER.COM
22 JulPaidwork breach exposes data of 23 million users: Check if you’re affectedA reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here's how to check if you're affected.MALWAREBYTES.COM
22 JulOpenAI models behind breach of Hugging Face systems, companies sayOpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by "by an autonomous AI agent."THERECORD.MEDIA
22 JulSuno, Paidwork Data Breaches Affect Tens of Millions of AccountsHackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftAn attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulJapanese food logistics giant recovers as extortion group claims cyberattackNichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.THERECORD.MEDIA
22 JulOpenAI models escaped containment and hacked a major AI application libraryThe attack is the first known instance of frontier models autonomously breaking out of a testing environment and into another company’s servers.CYBERSECURITYDIVE.COM
22 JulHow enterprise GenAI can amplify ransomware risk — and how to contain itEnterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI …BLEEPINGCOMPUTER.COM
22 JulNew Kimsuky campaign compromised South Korean software vendorsA North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.THERECORD.MEDIA
22 JulSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackSwiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]BLEEPINGCOMPUTER.COM
22 JulReal world incident response: Microsoft and AXA XL strengthen cyber resilienceOur collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilie…MICROSOFT.COM
🕵️ THREAT INTELLIGENCE 18[−]
22 JulISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 JulSmall teams are the heaviest users of AI coding agentsThe pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the …HELPNETSECURITY.COM
22 JulAI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - BSW #457America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American his…YOUTUBE.COM
22 JulAI models cheat on cybersecurity evaluations, then fail to admit itFrontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI). AISI defines cheating as a model doing something outside the bounds of what a task allows…HELPNETSECURITY.COM
22 JulFirst-Person Identity Theft StoryHarrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts…SCHNEIER.COM
22 JulBox expands enterprise AI governance with new agent security featuresoxBox has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and …HELPNETSECURITY.COM
22 JulArista adds AI-driven zero trust to VeloCloud SD-WANArista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices. Customers can leverage this integration to simplify the branch, collapsing multiple disparate …HELPNETSECURITY.COM
22 JulWhy Modern SOCs Need Multi-Layered DetectionsThe cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. T…THEHACKERNEWS.COM
22 JulGlow exits stealth with $180 million to secure the AI-enabled endpointGlow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish V…HELPNETSECURITY.COM
22 JulStrongestLayer Raises $4.1 Million in Seed Funding ExtensionThe startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulWhen Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account TakeoverIdentity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulThreatDown expands security visibility to AI tools and machine identitiesThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools ru…HELPNETSECURITY.COM
22 JulSwimlane AI SOC automates security operations for MSSPsSwimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into managed services, turning …HELPNETSECURITY.COM
22 JulPalo Alto Networks to Acquire Observability Platform Provider EmbraceAcquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulNext chapter: Restructuring GitHub’s bug bounty programGitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog .GITHUB.BLOG
22 JulYou Can't Ban Attacker AIAI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments. If organizations focus only on restricting AI instead of adopting effective …YOUTUBE.COM
22 JulWhite House accuses Chinese company of distilling Anthropic’s FableWhile distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberS…CYBERSCOOP.COM
22 JulMalware is targeting AI tools in software development environmentsThe worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
22 JulTrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryCybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades a…THEHACKERNEWS.COM
22 JulSol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.SENTINELONE.COM
📡 INFOSEC NEWS 18[−]
22 JulWeekly Threat Bulletin – July 22nd, 2026These are the top threats you should know about this week.F5.COM
22 JulBuilding a Security Company for a Market That Changes Every Four Months with Shahar Bahat of Pluto SecurityShahar Bahat is the CEO and co-founder of Pluto Security. With every employee now building things using tools like Cursor, Claude Code, Lovable, and n8n, security teams have no visibility into any of those layers. That is the problem Pluto is solving. She sat down with Gianna to …THECYBERWIRE.COM
22 JulMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsA single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it w…THEHACKERNEWS.COM
22 JulGlow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI eraGlow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.TECHCRUNCH.COM
22 JulStop renting storage space — this lifetime 2TB plan is yours for $59Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). [...]BLEEPINGCOMPUTER.COM
22 JulChick-fil-A loyalty accounts hijacked using stolen passwordsIf you have a Chick-fil-A One account, now is a good time to change your password—and make sure it's one you don't use anywhere else.MALWAREBYTES.COM
22 JulAdobe Chrome extension flaw let sites access private WhatsApp chatsThe Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]BLEEPINGCOMPUTER.COM
22 JulTrickBot Ditches HTTP for DNS Tunneling in Latest VariantNew TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP patternINFOSECURITY-MAGAZINE.COM
22 JulNew InfraTrust report reveals infrastructure flaws admins should patch firstEclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]BLEEPINGCOMPUTER.COM
22 JulOpening the Black Box: Agentless Threat Detection for Virtual AppliancesMapping FortiGate event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.WIZ.IO
22 JulIf you pay a hacker’s ransom, chances are that they’ll come back for moreThe long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.TECHCRUNCH.COM
22 JulOpenAI models escaped containment to hack Hugging Face.SolarWinds patches fifteen critical flaws. Business news: Neo emerges from stealth with $100 million.THECYBERWIRE.COM
22 JulWhen AI Attacks: OpenAI Models Autonomously Hack Hugging FaceAdvanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.DARKREADING.COM
22 JulRondo Meets Geoserver, (Wed, Jul 22nd)This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:
ISC.SANS.EDU
22 JulFrench Parliament greenlights social media ban for under-15sBoth houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.THERECORD.MEDIA
22 JulHow OpenAI’s human mistake led to the AI-powered hack on Hugging FaceOpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.TECHCRUNCH.COM
22 JulEndpoint security firm Glow emerges from stealth with $180 million.Neo has emerged from stealth with $100 million. Palo Alto Networks has agreed to acquire user-focused observability provider Embrace.THECYBERWIRE.COM
22 JulAI Threat Detection Is Not Enough Without Adversary IntelligenceThe 2026 emergence of Anthropic’s Claude Mythos Preview showed security leaders that AI can now find software vulnerabilities faster than the humans responsible for patching them.INTEL471.COM