HomeWeekly DigestsThis Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Jul 13 to Jul 20, 2026

Weekly threat intelligence digest from 352 items (26 critical, 248 high).

July 20, 2026 352 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST July 13 – July 20, 2026 This week the data shows a decisive move from “what we’re protecting” to “who we trust.” The most frequent breaches stemmed from compromised third‑party assets—code‑signing certificates stolen from DigiCert, malicious npm packages infecting 2.25 M downloads, and ransomware triggered by a single exposed cloud admin account. Credential‑stuffing, supply‑chain poisoning, and mis‑configurations are the vectors; the impact ranges from multi‑terabyte exfiltration to full‑scale production shutdowns. The pattern tells us that privileged access in the supply chain is the new attack surface. 👉 Access—not just vulnerability—is the dominant risk driver. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain breach → compromised code‑signing certs, npm packages, and SaaS admin consoles became initial footholds. * Privileged access amplifies impact → a hijacked admin credential enabled ransomware that halted Fairlife dairy production and exposed dozens of systems. * Visibility gaps → OT devices, cloud‑only workloads, and fourth‑party services remain largely outside most audit inventories. 🔍 WHAT CHANGED THIS WEEK * Credential‑theft tactics evolved: phishing now mimics finance‑workflow emails, and Chrome Sync abuse harvested millions of passwords in a single campaign. * Supply‑chain attacks accelerated: malicious AsyncAPI npm releases leveraged SLSA attestations, and code‑signing theft gave attackers the ability to weaponize trusted binaries. * Mis‑configurations resurfaced as a high‑impact vector, with cloud hosting providers and government sites inadvertently serving malware after a single server mis‑set. 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * SaaS platforms that grant admin API access to third‑party integrations (e.g., Zoom, WebEx, Azure AD). * CI/CD pipelines and GitHub Actions that lack strict workflow isolation—evidenced by the AsyncAPI npm compromise. * OT and industrial control systems using Siemens ROX II, ABB T‑MAC Plus, or Rockwell adapters that still run legacy firmware. * Cloud hosting providers and VPN services (1VPNS) that are listed in sanctions for enabling ransomware. * Identity‑as‑a‑Service (IdAM) solutions where OAuth client‑ID spoofing is observed in the wild. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. Map recent incidents to SOC 2 Trust Services Criteria. Identify which CC1‑CC5 controls (Security, Availability, Confidentiality, Processing Integrity, Privacy) are touched by supply‑chain and credential‑theft events. 👉 Ask: “Can we produce audit evidence that we continuously monitor these controls?” 2. Harden third‑party onboarding. Require vendors to provide up‑to‑date SBOMs, SLSA attestations, and signed code‑signing certificates; integrate these artifacts into your vendor‑risk management workflow. #Compliance #SOC2 #AuditReadiness #Cybersecurity #ThreatIntel #ContinuousCompliance #LiveThreat #VerisqAI

Articles Referenced in This Digest 352 items

Advisory (51)

CriticalCritical Zoom Flaw Could Let Attackers Take Over Windows Accounts
HighEU Orders Google to Open Android AI Features, Share Search Data With Rivals
HighApple Sued Over Hide My Email Privacy Claims
HighNew FCC Proposal Pits Phone Privacy Against Fraud Prevention
HighE.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
HighCISA Adds Three Known Exploited Vulnerabilities to Catalog
HighUK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
HighLeast privilege for AI agents: Identity, access, and tool binding
HighReading between the lines of a cyber insurance policy
HighWindows 11 24H2 Home and Pro reach end of support in 90 days
HighMicrosoft Urges Windows 11 Users to Install Updates Within Three Days
HighCMMC Assessment Pause Leaves Defense Contractors Facing a New Risk
HighUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
HighTego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
HighMultiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
HighGoogle is training AI on even more of your data now, unless you opt out - here's how
HighRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
HighMicrosoft Entra ID gets passkeys default authentication starting September
HighWindows 11 KB5101650 & KB5099414 cumulative updates released
HighMicrosoft releases Windows 10 KB5099539 extended security update
HighNATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
HighMicrosoft and Adobe Patch Tuesday, July 2026 Security Update Review 
HighVulnerability in FIFA’s Network
HighMicrosoft Entra ID authentication overhaul to start in September 2026
HighUS and allies warn of Russian critical infrastructure attacks
MediumHow a virtual LAN can better protect your home network - and the best way to get started
MediumGoogle Bets 'Agentic Defense' Strategy Can Outpace Attackers
MediumGold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
MediumWindows Server 2022 reach end of mainstream support in 90 days
MediumHHS Wants Input on Cyber, AI for Regulations on Clinical Labs
MediumWhy AI in Healthcare Demands Stronger Data Oversight
MediumNigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
Low1Password Lets Claude Sign In Without Revealing Passwords
LowOwn a Pixel? You can add device protection now for $5/month - but should you?
InformationalNew infosec products of the week: July 17, 2026
InformationalA hard drive reliability check on 341,263 drives, from 4TB to past 20TB
InformationalCISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
InformationalMicrosoft makes Windows SSO prompts easier to manage
InformationalTrump administration unveils AI-supported clearinghouse for cyber vulnerabilities
InformationalThis free Mac tool lets me see which apps are quietly accessing the internet - and block them fast
InformationalF5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trails
Informational July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days
InformationalHelping small businesses with free, hands-on cyber consultancy
InformationalAWS retools Security Hub for AI and multicloud threats
InformationalLatticeFlow AI connects governance frameworks with continuous AI risk monitoring
Informational[Video] Where protection starts: Cisco Talos Intelligence Integrations
InformationalManage Vendor Risk in a Few Practical Steps
Low12 YouTube default settings to change right now for a more enjoyable experience
LowMicrosoft starts testing cleaner Windows Search without ads
InformationalLumen expands managed detection and response with Cortex XSIAM integration
InformationalMicrosoft demystifies how Windows updates work

Breach (45)

CriticalGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
HighWorld's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
HighPaidwork - 23,272,765 breached accounts
HighSecurity Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
HighClickLock Mac Malware Traps Users in a Three-Day Password Loop
High23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach
HighA cyberattack hit Nichirei, one of Japan’s largest food companies
HighErnst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
HighErnst & Young discloses data breach after support system hack
HighAbbott probes two cyber incidents amid extortion claims
HighLessons Learned: US Cybersecurity Agency Leaked Secrets
High The backlash against Flock cameras is spreading
HighTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack
HighTwo Scattered Spider Members Sentenced to 5.6 Years Over TfL Cyberattack
HighAnubis ransomware: what you need to know
HighScattered Spider members jailed over Transport for London hack that cost £29 million
HighDaxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
High20+ Hijacked Government Websites Became
an Attack Channel
HighThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
HighTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
HighScattered Spider members behind TfL hack get five years in prison
High23andMe to pay $18 million in new genetics data breach settlement
HighCyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies
HighScattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack
HighClaude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
HighRussian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
HighAsyncAPI npm packages infected with credential-stealing malware
High23andMe reaches $18 million settlement with states for massive breach
HighFluke - 821,100 breached accounts
HighNew phishing kits target Microsoft 365 accounts, evade MFA
HighFinland issues wanted notice for hacker behind massive psychotherapy data breach
HighThe ransomware negotiator who was working for the other side
High The inside job that cost ransomware victims millions
HighMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended
HighAttacker Used AI to Build Custom PowerShell Recon Malware
HighGrok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
HighJapan's largest taxi operator shuts systems after cyberattack
HighRussian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach
HighJscrambler npm Breach Exposes Developers to Malware
High A week in security (July 6 – July 12)
HighLidl discloses online shop breach after service provider hack
HighLessons Learned from CISA’s Recent GitHub Leak
HighDutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
MediumKlueセキュリティインシデントとRecorded Futureへの影響

Ransomware (6)

HighSpirals ransomware locks down victim systems in under 24 hours
HighDairy company Fairlife suspends production in US after cyber incident
HighRansomware attack halts Coca-Cola’s Fairlife US milk production
HighCoca-Cola says Fairlife ransomware attack halts US dairy production
HighSpirals: New Stealthy Ransomware Deployed Against Asian IT Company
HighNew Spirals ransomware encrypts victim network in under 24 hours

ThreatIntel (171)

CriticalAdaptiva simplifies secure patch management for air-gapped networks
HighSleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
HighHackers abuse ViPNet software to target Russian govt agencies
HighUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
HighWeek in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
HighDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
HighThe Future of Age Verification: Your Face Never Leaves Your Device
HighMicrosoft warns of surge in ACR Stealer attacks on customers
HighHugging Face Says Autonomous AI System Executed Multi-Stage Cyberattack
HighAI Hardware, App Store Shifts, and Security Scares Define This Week in Tech
HighInc Ransomware Exploits SonicWall SMA Zero-Days
HighISMG Editors: AI Phishing Kits Go Mainstream
HighOpenAI Warns GPT-5.6 File Deletions Stem From Full Access Mode
High“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware
HighFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
HighNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
HighSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
HighInside the Search for "Clean" Residential Proxies for Carding
High How to use GitHub safely
HighTracking Advanced Persistent Threat Groups | Recorded Future
HighMicrosoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
HighNew Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
HighThe script, not the voice, is what makes AI voice phishing work
HighPrompt injection is becoming the XSS of the web agent era
HighScammers weaponize FaceTime to drain bank accounts
HighNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
HighACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
HighThe Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
HighUS charges two over laundering $43 million from investment fraud
High1M+ Emails Use Hidden Text to Dupe AI Security Filters
HighSenator calls on Rubio, Blanche to push back against Canadian surveillance legislation
HighACR Stealer: Two observed intrusion chains amid increased threat activity
HighBegun, the Patch Wars have
HighSpaceXAI Open-Sources Grok Build After Privacy Backlash
HighThe Biggest Data Breaches of 2026 So Far, Ranked by Impact
HighAI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
HighHelloNet campaign — new malicious modules launched through the ViPNet update system
HighNew Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
HighNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
HighNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
HighAI Agents Broke the Security Playbook. Here's What Replaces It.
HighNew OkoBot framework deploys 20 payloads to steal data, crypto
HighNew ClickLock macOS malware traps users into revealing login password
HighSandworm hackers have a CAPTCHA trick for Ukrainians
HighUK Sees Data Infrastructure, Water System Cyberattack Risks
HighGoogle Makes Security Objections to EU Order Opening Android
High Samsung backs down on threat to delete health data
HighUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
HighAustralian Enterprises At Risk as Anthropic Finds Hackers In Claude Code
HighTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All
HighOkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
HighGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
HighPolice take down investment fraud network that stole €100 million a month
HighRomania’s land registry hit by cyber attack, data allegedly for sale
HighOpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
HighUnpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
HighRussian hackers trojanize WebEx, Zoom apps to push Starland malware
HighIdentity Attacks Overtake Exploits as Top Ransomware Cause
HighUnpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
HighApple Warns Millions of iPhone Users: FaceTime Scams Are Spreading
HighFake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones
HighThe Shift: A New Era of AI Regulation
HighI let ChatGPT Work and Claude Cowork loose on my files - only one made me nervous
HighNew Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat
HighThreat actor impersonated hundreds of brands on GitHub to push infostealer malware
HighLabubaRAT malware infiltrates Windows systems while posing as NVIDIA software
HighSASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
HighOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
HighTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
HighWe built a vulnerability vending machine: AI tokens in, zero-days out
HighGoogle Gemini CLI abused as a hacking agent, malware botnet operator
HighDutch police bust investment fraud ring stealing over €100 million
HighWhen Routine Becomes the Threat: The Evolution of Finance-Themed Phishing
HighDaxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
HighClaude Flaw Automatically Sends Malicious Prompts to AI Agents
HighIs 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
HighLAPD sidelines relationship with license-plate reader company Flock Safety
HighDutch police dismantle global crypto investment scam, arrest alleged mastermind
HighFeds Target Widely Used Russian Bulletproof Hosting Services
HighTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
HighClickFix is changing the economics of social engineering
HighMicrosoft: Some Dell PCs shut down after recent Windows updates
HighAustralian Enterprises At Risk as Anthropic Finds Hackers In Claude Code
HighU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
High“Context bombs” can frustrate AI-driven attacks, researchers found
HighNew macOS malware steals passwords by posing as Apple’s crash-reporting tool
HighOAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
HighStudy of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
HighLabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
HighYou Don't Have to Run an Exploit to Know If You're Vulnerable
HighLastPass, Bitwarden users targeted with fake security alerts
HighProgress confirms ShareFile zero-day flaw behind Storage Zone shutdown
HighNearly 300 GitHub repos pose as legit software to push malware
HighSpanish Police take down €140 million cyber fraud ring, arrest four
HighUS unseals indictment against alleged operators of Russian bulletproof hosting service
HighHow Qualys ETM Identity Detects Identity-Based Attacks Faster
HighThe serpent’s tongue: Luring the Python out of its den
HighClickFix's Mushrooming Ecosystem Demands New Defense Tactics
HighThe FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
High Warning: Scammers are using FaceTime to empty bank accounts
HighMillions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
HighYour vendor’s vendor might be the real breach risk
HighNew tutorials on underground hacking forums have roughly doubled
High148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
HighU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
HighUS sanctions VPN, malware providers for enabling ransomware attacks
HighNew CrashStealer malware poses as Apple crash reporting tool
HighMeta Removes Muse Image Instagram Feature After Consent Backlash
HighWeak Security Continues to Fuel Russian Cyberattacks
HighIs that QR code a trap? How to spot quishing scams before it's too late
HighEU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe
HighThe AI Supply Chain Is Your Latest Unguarded Attack Surface
HighDefending SaaS-based applications against ShinyHunters OAuth abuse
High Ghostcommit attack hides malicious AI instructions in images
HighMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
HighAttacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
HighMeta Files Patent for AI That Can Listen All Day and Track How You're Feeling
HighForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
HighNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
HighCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
HighUK charges suspects linked to Russian Coms call spoofing platform
HighAustralia Alerts Organizations to Ongoing CMS Exploitation Attacks
HighEU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
HighOAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration
High99.9% of fixable AI vulnerabilities remain unpatched
MediumScans for Hikvision Intelligent Security API, (Sun, Jul 19th)
MediumClaude can now sign into websites with 1Password without exposing your credentials
MediumArmenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
MediumBreach Roundup: Extortionists Annoyed by Waning Ransomware
Medium1Password's new Agentic Mode lets Claude log into your accounts without seeing your credentials
MediumTenable One unifies code risks with enterprise exposure data
MediumI tested my USB-C cables with this free Mac app - some weren't what they claimed
MediumGoogle Search will let you instantly generate AI images for free - here's how
MediumQ2 2026 Cyber Attacks Statistics Infographic
MediumGreenhat Announces Successful Delegation at Web Summit Vancouver 2026
MediumTelegram’s t.me Links Go Offline After Registry Places Domain on serverHold
MediumDon't let an AI chatbot pick your password, ever
MediumThe best defense against AI attacks turns out to be a skeptical human
MediumTorq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations
MediumTurning the Tables on Email Scammers With 'ScamBuster'
Medium'Yellow Teams' Are Defining the Future of AI Security
MediumCloudflare Precursor uses continuous behavioral analysis to stop advanced bots
MediumEnterprises are rethinking where their AI applications run
MediumA hardware security AI assistant that checks chips for hidden backdoors
InformationalOak Lands $60M Seed to Reinvent Identity Governance With AI
InformationalH1 2026 Cyber Attacks Statistics Infographic
InformationalLineation.ai focuses on runtime security for autonomous AI agents
InformationalIntruder brings AI-powered, on-demand penetration testing to web applications
InformationalCribl Targets TTP-Based Detection With CardinalOps Purchase
InformationalAnnouncing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans
InformationalApple Tests New iMessage Warning for Malicious Messages
InformationalInsignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required
InformationalI highly recommend Nomad's chargers, phone cases, and watch bands - and my favorites are on sale now
InformationalHow to use Gemini to plan your next summer vacation - in minutes
Informational Claude for Chrome flaw could let rogue extensions access your Gmail
InformationalCribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
InformationalTurning threat intelligence into decisive action with Defender Experts
InformationalBinary Defense’s NightBeacon CMD helps enterprise SOC teams automate threat investigations
InformationalHow to download iOS 27 right now (and which iPhone models support it)
InformationalHow to download iPadOS 27 right now - and which models support it
InformationalThe only Apple Watch strap you'll ever need is down to its lowest price yet
InformationalHow Pentera Turns AI Security Workflows into Validation Engines
InformationalQ2 2026 Cyber Attacks Statistics
InformationalCybersecurity jobs available right now: July 14, 2026
InformationalFake smart home residents could stand in for real ones in security research
InformationalISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)
InformationalGet Peace of Mind: Protect Data for Life With BigMind DR for $59.99
InformationalTidal Cyber connects assets, vulnerabilities, and threats through Threat-Led Defense
InformationalBreach at the Beach: Play the Ultimate Entra ID CTF
InformationalCynative: Open-source deep research agent
InformationalFastNetMon eliminates third-party bgp lookups with Netomics

Vulnerability (79)

CriticalCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
CriticalSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
CriticalWordPress Core "wp2shell" RCE flaws get public exploits, patch now
CriticalTwo new high severity WordPress vulnerabilities, patch immediately!
CriticalU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
CriticalCISA Adds FortiSandbox Bugs to KEV Catalog
CriticalNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
CriticalThree Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
CriticalCISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CriticalCISA urges immediate action on actively exploited Fortinet flaws
CriticalNew Windows LegacyHive zero-day gives hackers admin privileges
CriticalZoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
CriticalZoom Patches Critical Windows Flaw That Could Enable Account Takeover
CriticalCISA orders feds to patch actively exploited Oracle flaw by Saturday
CriticalFirefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
CriticalAI-driven bug hunting fuels record Microsoft Patch Tuesday
CriticalSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
CriticalMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
CriticalSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
CriticalRockwell Automation 1715-AENTR EtherNet/IP Adapter
CriticalABB T-MAC Plus
CriticalSAP warns of critical flaws in NetWeaver and Commerce Cloud
CriticaliCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
HighOpenSSL Fixes HollowByte Memory Exhaustion Bug
HighUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives
HighGoogle’s Gemini lets strangers send messages from your locked Android phone
HighOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
HighHollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
High Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
HighU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
HighClaude for Chrome Flaw Puts Gmail at Risk From Rogue Extensions
Highn8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
HighClaude Chrome extension flaw lets malicious extensions trigger AI actions
HighRockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
HighAutomationDirect Productivity Suite
HighRockwell Automation Arena
HighNASA Core Flight System (cFS) Health & Safety (HS) Application
HighRockwell Automation FactoryTalk DataMosaix
HighSiemens SICAM 8
HighRockwell Automation Flex 5000 Adapter
HighRockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
High Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom
HighResearcher Drops 9th Windows Zero-Day
HighChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
HighMicrosoft patches record 570 Windows security bugs with two exploited zero days - update now
HighZDI-26-404: Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
HighZDI-26-405: X.Org Server GLX Extension Use-After-Free Privilege Escalation Vulnerability
HighZDI-26-406: X.Org Server BitmapScaleBitmaps Integer Overflow Privilege Escalation Vulnerability
HighZDI-26-409: X.Org Server Glamor Font Heap-based Buffer Overflow Privilege Escalation Vulnerability
HighZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
HighZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability
HighZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
HighZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability
HighZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability
HighZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
HighZDI-26-420: Adobe Creative Cloud AGSService Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability
HighZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability
HighZDI-26-428: WatchGuard FireWare OS admd Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighZDI-26-432: G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
HighZDI-26-435: (Pwn2Own) Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability
HighZDI-26-436: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability
HighZDI-26-437: (Pwn2Own) Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
HighZDI-26-438: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
HighZDI-26-439: Fuji Electric Tellus pcid64 Driver Exposed Dangerous Method Local Privilege Escalation Vulnerability
High2-Click Cursor Exploit Enables Dev Environment Takeover
HighFreeRDP 3.29.0 security update resolves 22 advisories
HighMicrosoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
High11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
HighResearchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
HighMicrosoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
HighCursor IDE Auto-Executes Malicious Code in Poisoned Repos
HighABB Ability Edgenius
HighSecurity threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
MediumSALTO ProAccess Space
MediumZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability
MediumZDI-26-433: (Pwn2Own) Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability
MediumABB Advant Master Online Builder
LowZDI-26-434: (Pwn2Own) Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests