HomeWeekly DigestsThis Week
LiveThreat Threat Intelligence

Weekly Threat Intelligence Digest — Jul 20 to Jul 27, 2026

Weekly threat intelligence digest from 366 items (43 critical, 252 high).

July 27, 2026 366 articles analyzed
LIVETHREAT WEEKLY THREAT DIGEST July 20 – July 27, 2026 This week the most visible danger was not a single vulnerability but the exploitation of privileged access that lives in trusted third‑party platforms. Ransomware groups leveraged VPN backdoors in Palo Alto, SonicWall and Check Point, while AI‑driven actors hijacked cloud‑hosted API services and CI/CD runners to reach downstream data stores. Supply‑chain breaches – from PTC Windchill to OpenAI’s model sandbox – cascaded into massive data loss and operational shutdowns. The pattern is clear: 👉 Access to privileged vendor services, not the underlying software flaw, is the primary attack surface. 🚨 EXECUTIVE RISK SNAPSHOT * Supply‑chain entry → compromised VPN appliances, SaaS admin consoles and CI/CD runners opened the door to enterprise networks. * Privilege amplifies impact → a single hijacked cloud admin account enabled ransomware on AI model repositories and exfiltration of terabytes of data. * Blind asset inventory → OT/PLC devices and third‑party SDKs remain outside most audit scopes, creating unseen exposure. 🔍 WHAT CHANGED THIS WEEK * AI‑enabled tooling accelerated vulnerability discovery, pushing record‑high patch releases and leaving organizations chasing remediation. * Credential‑theft campaigns increasingly target service‑account passwords, giving attackers footholds in cloud and API environments. * Attackers are weaponizing “agentic” AI – both as a delivery mechanism (JadePuffer ransomware) and as an autonomous adversary (OpenAI‑Hugging Face breach). 🎯 WHERE YOU ARE MOST LIKELY EXPOSED * VPN and remote‑access gateways – Palo Alto GlobalProtect (CVE‑2026‑0257), SonicWall SMA (CVE‑2026‑15409/15410), Check Point SmartConsole (CVE‑2026‑16232). * Cloud‑hosted SaaS admin portals – ServiceNow AI Platform (CVE‑2026‑6875), Oracle E‑Business Suite (CVE‑2025‑61882), generic cloud hosting providers. * API and AI platforms – OpenAI, Hugging Face, Langflow (CVE‑2026‑0770), GitHub Actions runners used to attack cPanel/WHM. * ERP and PLM systems – PTC Windchill/FlexPLM (CVE‑2026‑12569), Oracle EBS. * CI/CD pipelines and third‑party SDKs – compromised GitHub Actions, malicious PyPI packages. ⚡ WHAT COMPLIANCE & SECURITY LEADERS SHOULD DO THIS WEEK 1. Refresh vendor‑risk assessments → map each third‑party to SOC 2 CC6.1 (Logical Access) and capture evidence of privileged‑access reviews. 👉 Ask: “Can we produce a current attestation that every VPN or SaaS admin account is covered by MFA and least‑privilege?” 2. Harden privileged access controls → enforce MFA, conditional access, and just‑in‑time provisioning for VPN, cloud admin and API keys. 👉 Verify that audit logs show real‑time alerts on privileged‑access anomalies. #Compliance #SOC2 #AuditReadiness #Cybersecurity #ThreatIntel #ContinuousCompliance #LiveThreat #VerisqAI

Articles Referenced in This Digest 366 items

Advisory (56)

HighGitHub, PyPI add time-based defenses against supply chain attacks
HighOpenAI confirms ChatGPT is down worldwide
HighGoogle Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices
HighMicrosoft blames massive Microsoft 365 outage on maintenance bug
HighUS House Votes to Extend Cyber Sharing Law for 10 Years
HighMicrosoft tightens Windows enterprise activation security
HighApple Fixes Hide My Email Bug After Yearlong Delay
HighEU fines Google $1 billion for search, app store antitrust violations
HighFedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
HighMicrosoft 365 outage affects Teams, SharePoint and other services
HighCISA Again Sounds Warning Over Exposed PLCs
HighState Department imposes visa restrictions on foreign cyber scammers
HighMulti-patch vulnerability fixes can leave open source exposed
HighMicrosoft working to fix Exchange Online mailbox quarantine issue
HighFederal agencies broaden alert on Iran-linked OT attacks
HighExtension of CISA 2015 info-sharing protections passes as part of House’s defense bill
HighCISA Adds Two Known Exploited Vulnerabilities to Catalog
HighOracle Critical Patch Update, July 2026 Security Update Review
HighFrance Bans Social Media for Under-15s, Requires Age Checks
HighFrench Parliament greenlights social media ban for under-15s
HighMicrosoft to stop Exchange 2016 / 2019 security updates in October
HighAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
HighCISA Adds Four Known Exploited Vulnerabilities to Catalog
HighWindows KB5121767 OOB update fixes shutdowns on some Dell PCs
MediumMeta tackles AI-generated accounts with a free Facebook verification badge
MediumAndy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry
MediumGoogle will let you upload a video selfie to recover your account - but should you?
MediumPyPI hardens package security with new upload restrictions
MediumMicrosoft shares manual fix for WSUS sync delays and timeouts
MediumAWS Billion-Dollar Software Bug Explained
MediumMicrosoft confirms Windows Server Update Services sync delays
InformationalClaude Opus 5 sharpens coding and cybersecurity work on AWS
InformationalThe Journey towards Logically Air-Gapped Deployment
LowGoogle Adds Selfie Video Sign-In to Help Users Recover Locked Accounts
InformationalGoogle gives developers an AI bug hunter that also writes patches
InformationalAI image fraud will cost $40 billion next year - can these international standards help?
InformationalCisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
InformationalWindows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained
InformationalGoogle Adds Selfie Video Recovery for Users Locked Out of Their Accounts
InformationalAxonius expands Asset Cloud with Cyber Assets and Exposures enhancements
InformationalGitHub revamps bug bounty program with new VIP tier, payout changes
InformationalGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
InformationalFirefox 153 enables Containers by default, and you can create your own - here's how
InformationalOpenAI Presence connects AI agents to enterprise data with built-in guardrails
InformationalReal world incident response: Microsoft and AXA XL strengthen cyber resilience
InformationalArista adds AI-driven zero trust to VeloCloud SD-WAN
InformationalBox expands enterprise AI governance with new agent security featuresox
InformationalSASE, AI and Zero Trust: What InfoSec & IT Leaders Need to Plan for Next
LowAndroid backups count toward your 15GB Google storage limit now - how to check your settings
InformationalThis Android 17 setting logs suspicious activity on your phone for troubleshooting - turn it on ASAP
InformationalCisco’s open-weight Antares models make vulnerability localization cheaper
InformationalDruva brings backup, recovery and governance to AI workloads
InformationalTaiwan to slow mobile data during national resilience drills
Informational3 Ways to Defend Against LOTL Attacks Now
InformationalAn AI SOC Evaluation Guide for Security Leaders
InformationalMeet Dusseldorf, Microsoft’s open-source out-of-band security platform

Breach (74)

CriticalSonicWall SMA zero-days were exploited weeks before disclosure
CriticalSonicWall SMA1000 flaws exploited as zero-days to push custom malware
HighSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
HighSecurity Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION
HighWeekly Update 514: This Week in Data Breaches
HighAustralian energy provider Origin Energy disclosed a data breach impacting customer data
High OpenAI’s agent escaped its sandbox during a security test
HighVatican's Official Prayer App Leaks 700K+ Global Users' PII
HighEscape Artists: 'Incorrigible' AI Models Resist Rehabilitation
HighChick-fil-A data breach affects more than 13,000 customers
HighOnTrac notifies customers of data breach after network hack
HighPatient Sues Abbott Labs, Exact Sciences in Data Theft
HighWhen the Sandbox Won't Hold: Lessons From Hugging Face
HighHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
High'Wrench' attacks against crypto holders appear to be on the rise
HighRansomware gangs go after EMEA healthcare’s supply chain
HighRussian hackers exploit unpatched Zimbra servers to steal emails
HighOne Password Mistake Helped Hackers Access Chick-fil-A Account
HighUK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
HighOpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
HighOpenAI's attack agent did exactly what it was told - just more relentlessly than expected
HighHow attackers hosted a fake Claude download page on the claude.ai domain
HighRussian hackers exploit Zimbra zero-click flaw for email theft
HighFake Claude app promoted by Bing ads pushes SectopRAT malware
HighAustralian energy provider Origin says data breach exposes client data
HighMajor Australian energy supplier confirms customer data compromised
HighMonths-long breach exposes South Korean diplomats’ personal data
High Chick-fil-A loyalty accounts hijacked using stolen passwords
HighNew Data Shows Suno Breach Affected 55M Accounts
HighThe OpenAI Hack Was a Mini Paperclip Maximizer
HighSmashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
HighOpenAI: Our models breached Hugging Face during a cyber capability test
HighSouth Korea discloses data breach impacting diplomats worldwide
HighUpbound says hack caused $13 million in fraudulent Acima leases
HighOpenAI Seeks Agent Trust After Hugging Face Breach
High Paidwork breach exposes data of 23 million users: Check if you’re affected
HighAppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
HighOpenAI Models Escaped Test Environment and Breached Hugging Face
HighOpenAI models behind breach of Hugging Face systems, companies say
HighJapanese food logistics giant recovers as extortion group claims cyberattack
HighNew Kimsuky campaign compromised South Korean software vendors
HighEU Financial Institutions Leak Data Through Cookie Trackers
HighFirst-Person Identity Theft Story
HighOpenAI says its AI models hacked Hugging Face during testing
HighChick-fil-A discloses data breach after credential stuffing attacks
HighApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
HighOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
HighErnst & Young breach exposes client tax data - find out if you're at risk and what to do next
HighServices Firm ApolloMD Settles Hack Lawsuit for $4M
HighOpenAI Models Escaped Sandbox, Breached Hugging Face
HighCraneware Confirms Data Theft After Cyberattack, Investigations Underway
HighQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
HighSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
HighEstée Lauder discloses data breach tied to Oracle EBS vulnerability
High Healthcare giant Abbott probes two cyber incidents amid extortion claims
HighHugging Face Says Autonomous AI Agent System Breached Production Infrastructure
HighIndia says allegedly leaked nuclear plant files pose no safety risk
HighAn AI agent breached Hugging Face before an AI defender caught it: What users should do next
HighItaly fines WINDTRE €1.7 million over security flaws behind two data breaches
HighPaidwork breach exposes sensitive data of 23 million user
HighHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
HighHackers steal $23.7 million in crypto from Ostium in off-chain attack
HighEstée Lauder discloses data breach via Oracle E-Business flaw
HighHugging Face Says Autonomous AI Agents Breached Data, Credentials
HighCraneware, Abbott Probe Separate Health Data Theft Incidents
HighSuno - 55,282,226 breached accounts
HighFBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
HighSoftware provider to more than 2,000 US hospitals says hackers stole employee and customer data
HighRomania races to restore land registry after cyberattack disrupts property market
HighHackers were inside South Korea's diplomat training system for 9 months
HighAI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
HighHugging Face breached by autonomous AI agent
HighHugging Face discloses breach linked to autonomous AI agent
MediumKenya probes hack of president's website after bitcoin ransom demand

Ransomware (13)

CriticalClop ransomware targets Windchill, FlexPLM in data theft attacks
CriticalChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
CriticalCritical Palo Alto VPN bug now exploited by Qilin ransomware gang
HighChaos ransomware deploys browser-based msaRAT to evade network detection
HighSwiss train maker Stadler refuses Everest $12 million ransomware demand
HighRansomware Attack Puts a Chill On Japanese Frozen-Food Chain
HighSwiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
HighSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
HighJadePuffer returns with ransomware built to target AI models and infrastructure
HighAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
HighA new extortion cocktail: office printers, small ransoms, and BitLocker
HighNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
HighJadePuffer agentic attacks now target AI model data with ransomware

ThreatIntel (143)

HighHackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
HighScans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
HighMalvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
HighIran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
HighShinyHunters data leaks fuel $2,000 sextortion email scam
HighMalicious sites use JavaScript to build malware in browser memory
HighSteam forum ClickFix attacks infect gamers with XMRig cryptominers
HighDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
HighCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
HighCTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
High Google wants to store a selfie video of your face
HighEuropol flags 4,340 URLs for removal in 'The Com' crackdown
HighHackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
HighHermes AI agent used to automate attack on Thai Finance Ministry
High Beyond the Play Store: How Android threats really spread
HighRansomware is the Scoreboard
HighFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
HighGolden Chickens Resurfaces With Four New Malware Families and Modular Implants
HighSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
HighBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
HighRussian Global Webmail Espionage
HighRansomware in 2026: More groups, more victims, no slowdown
HighThe best-funded companies open the most phishing attachments
HighThe automotive software vulnerabilities hiding in your dashboard
HighRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
HighWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
HighRussian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
HighHackers abuse Notepad++ plugins to stealthily install malware
HighNew Dolphin X malware uses AI to rank high-value targets
HighRussian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
HighApiiro CEO: Coding Agents Are the New Enterprise Perimeter
High5 Key Takeaways from the Cofense 2026 Mid-Year Threat Report Webinar
High1-15 July 2026 Cyber Attacks Timeline
High1-15 July 2026 Cyber Attacks Timeline Infographic
HighTAG-195 Upgrades MaaS Ecosystem with Modular Tools
HighAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
HighHow Synthetic Identity Fraud is Coming for Machine Identities
HighChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
HighThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
HighInternational alert spotlights Russia-linked attacks on Zimbra webmail
HighBrazilian Banking Trojan Actively Spreading in Portugal
HighAgentic AI Challenges Progress in Confidential Computing
HighEnd-to-End Encryption and “Going Dark”
HighShadow AI is becoming enterprise security’s biggest blind spot
HighChaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
HighNew msaRAT malware uses Chrome, Edge browsers to route C2 traffic
HighThird-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
HighWhen AI Attacks: OpenAI Models Autonomously Hack Hugging Face
HighFake Bahrain Alert App Deploys Android Surveillance Malware
HighAttackers Are Learning to Live Off the AI Toolchain
HighNew InfraTrust report reveals infrastructure flaws admins should patch first
HighHow enterprise GenAI can amplify ransomware risk — and how to contain it
HighHow AI-Driven Robotics Expands Industrial Cyber Risk
HighLawsuit Claims ChatGPT Dished Out Dangerous Health Advice
HighPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
HighWhy Modern SOCs Need Multi-Layered Detections
HighPolice dismantle Kratos phishing platform behind 15,000 monthly campaigns
HighAI models cheat on cybersecurity evaluations, then fail to admit it
HighLookout identifies exploitable vulnerabilities in mobile apps
HighUS seizes over 1,000 domains used for illegal World Cup 2026 streams
HighTrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
HighClick to Sync: From Google Ads Maintenance Notice to Credential Theft
HighChoose Wisely: AI-Generated Coding Risk Varies, a Lot
HighHacker Turns AI Jailbreaks Into Offensive Attack Platform
HighRansomware Is Accelerating, But It's Not Because of AI
High90,000 Flock cameras have quietly gone up in the US: What they track and how to check your city
HighAI agents tricked into recommending malicious GitHub repositories
HighClosing the Identity Gaps in Critical Infrastructure Security
HighFakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
HighPolice dismantle Kratos phishing platform, arrest developer
HighThe Next Crypto Fraud Frontier May Be Space
High AI nudify apps spark legal scrutiny of Apple and Google’s profits
High Don’t trust that “FBI agent” in your DMs
High New ClickLock Stealer locks your Mac until you hand over your password
HighFake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims
HighIran War Cyber Threat Landscape | A Midyear Assessment on What Matters
HighNew Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
HighNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
HighN-day is Becoming N-Hour. Patching Faster Won't Save You.
HighOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
HighRockwell Automation 1734 POINT I/O
HighManual Patching Can’t Outrun AI. Automated Remediation Can.
HighMIT to Become Hotbed of AI Video Surveillance
HighAI agents are still logging in as humans
HighNobody was checking the drives that encrypt your laptop
HighOpen-source maintainers still work underfunded as sponsorship crosses $100 million
HighFake FBI agents target people who already got scammed
HighUS seizes over 1,000 websites in FIFA World Cup piracy crackdown
High The Odyssey piracy scams appear within hours of the movie’s release
HighFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
HighDutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
HighAttackers Combo Up Evasion Tactics for BEC Phishing
HighThe Odyssey piracy scams surface hours after its theatrical debut
HighNew HollowGraph malware uses Microsoft Graph for stealthy C2 comms
High Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
HighThe Hidden Risk in Enterprise AI Agents: Ungoverned Context
HighRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
HighMythos Didn't Break Your Security Program. Your Exposure Window Could.
HighRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
HighHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HighExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
HighMore than 1,000 domains illegally streaming World Cup games seized, DOJ says
HighUnpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service
HighOn Flock License Plate Tracking Cameras
HighA forensic tool for backdoored code completions in AI assistants
HighMore alerts are making your team slower, and an outcome-based SOC fixes that
HighThe Windows 10 hangover is becoming a security problem
Medium Don’t get fooled by TikTok resin art scams
MediumGoogle’s newest sign-in method asks you to look at the camera
MediumDon’t swing at everything
MediumCobalt adds Autonomous Pentest to scale application security testing
MediumIBM Bets on Multi-Billion-Dollar Open-Source Patch Business
MediumEmail threat landscape: Q2 2026 trends and insights
MediumGoogle Holds Back Gemini 3.5 Flash Cyber as CodeMender Enters Preview
MediumI gave Perplexity's agentic AI 5 complex tasks to run on my Mac - and I'll do it again
MediumThreatDown expands security visibility to AI tools and machine identities
MediumSmall teams are the heaviest users of AI coding agents
MediumDNI nominee Clayton wins Senate panel’s approval
MediumWeekly Update 513: Clauding The Home Network
MediumTeleport enhances Identity Security platform with new AI agent behavior controls
MediumPR3TACK preemptive framework maps threats before attackers use them
MediumFlock Safety kills acoustic system designed to detect 'human distress'
MediumRemediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
MediumNeo Launches With $100M to Guard Agentic Enterprise Software
MediumLG Monitors Spotted Installing Adware-Like App on Windows PCs
InformationalISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
InformationalProduct Showcase: AppViewX Agent Identity Security
InformationalAstelia extends reachability analysis with agentic AI for vulnerability management
InformationalModern Attack Vectors | Recorded Future
InformationalSol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?
InformationalHow to use themes in Google Messages so you never send the wrong person the wrong text again
InformationalGoogle’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
InformationalGlow exits stealth with $180 million to secure the AI-enabled endpoint
InformationalGlow Launches With $180M to Thwart AI Risk at the Endpoint
InformationalCaptive Portal Detection, (Tue, Jul 21st)
InformationalHow Zero Networks Targets AI Agents With Microsegmentation
InformationalFig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
InformationalGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
InformationalT-Mobile will pay for your first month of 5G home internet, and give you up to $200 back - here's how
InformationalAWS wants GuardDuty to automate the first steps of threat investigations
InformationalShufti simplifies cross-border compliance with the Glocal Platform
InformationalThreat Hunting: A Guide | Recorded Future
InformationalISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)

Vulnerability (80)

CriticalWeek in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
CriticalFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
CriticalDefault Azure Automation Setting Enables Cross-Tenant Identity Takeover
CriticalKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
CriticalBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
CriticalChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
CriticalCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
CriticalU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
CriticalPanduit IntraVUE
CriticalJohnson Controls C-CURE 9000 and Victor application server
CriticalCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
CriticalCheck Point patches actively exploited SmartConsole authentication bypass flaw
CriticalAttackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
CriticalCheck Point warns of SmartConsole zero-day exploited in attacks
CriticalRefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) 
CriticalAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
CriticalCISA orders urgent action on actively exploited Langflow RCE flaw
Critical What happens if you visit a WordPress site hacked through wp2shell?
CriticalQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
CriticalZimbra 10.1.20 patches multiple security issues, including a critical command injection bug
CriticalPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
CriticalCritical wp2shell WordPress flaws exploited to install webshells
CriticalCritical SharePoint RCE flaw exploited to steal machine keys
CriticalCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
CriticalWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
CriticalZimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
CriticalCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
CriticalSiemens Opcenter X
CriticalSiemens CADRA
CriticalSiemens SIDIS Secured SmartPlug
CriticalTycon Systems TPDIN-Monitor-WEB2
CriticalWordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Critical'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
CriticalServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
CriticalVolexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
CriticalCVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
CriticalCritical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
CriticalCritical ServiceNow code execution flaw now exploited in attacks
HighResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
HighNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Highta458 roundpress exploits
HighTA488 Targets Zimbra Mailservers with Half-Click Exploits
HighZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
HighZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability
HighZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability
HighZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability
HighMZ Automation lib60870
HighMZ Automation libIEC61850
HighRockwell Automation ThinManager
HighWeintek cMT3092X
High WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
High Millions of cars could be tracked and unlocked by a hidden security flaw
HighNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
HighClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
HighFlaws in Passkey Implementation Show Old Attacks Still Work
HighNew RefluXFS Linux flaw lets attackers gain root privileges
HighAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
HighUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
HighAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
HighCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
HighNew Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
HighHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
HighZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
HighZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
HighHackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn
HighMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
HighRockwell Automation FactoryTalk Services Platform
HighRockwell Automation Studio 5000 Logix Designer
HighRockwell Automation 1718-AENTR/1719-AENTR
HighSiemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
HighSiemens IAM Client
HighCVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
HighWindows LegacyHive zero-day flaw gets free, unofficial patches
HighA Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution
HighCursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
High A week in security (July 13 – July 19)
HighNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
High⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
MediumZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
LowJohnson Controls XAAP Android

Daily breach, advisory, and vulnerability briefs publish every weekday.

View Live Breach Feed ← All Weekly Digests