Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
27 Jul 2026
Daily Cybersecurity Briefing — July 27, 2026
5 CVEs 3 threats 4 news items
Critical Vulnerabilities 5
CVE-2026-57092 CVSS 9.9 Microsoft Windows VMSwitch (Hyper-V)

Critical use-after-free (CWE-416) in Windows VMSwitch allows an authenticated attacker to elevate privileges over a network with low attack complexity. Can be exploited to escape a VM boundary and compromise the host system. Part of the record-breaking July 2026 Patch Tuesday.

Source
CVE-2026-56155 CVSS 7.8 Microsoft Active Directory Federation Services (AD FS)

Elevation of privilege vulnerability caused by insufficient access-control granularity. Exploited in the wild as a zero-day before Microsoft released a patch. Allows an authorized attacker to gain elevated privileges locally.

Source
CVE-2026-56164 CVSS 8.1 Microsoft SharePoint

Elevation of privilege vulnerability in SharePoint. Exploited in the wild as a zero-day. Attackers are actively targeting on-premises SharePoint servers. Urgent patching recommended.

Source
CVE-2026-63030 CVSS 9.8 WordPress Core (wp2shell)

Critical REST API batch-route confusion vulnerability in WordPress Core that disables an authorization check, allowing unauthenticated attackers to achieve remote code execution. Added to CISA KEV catalog on July 21, 2026.

Source
CVE-2026-60137 CVSS 8.5 WordPress Core

SQL injection vulnerability in WordPress Core WP_Query component, actively exploited in the wild. Allows unauthenticated attackers to compromise websites and potentially achieve remote code execution when chained with other flaws. Added to CISA KEV.

Source
Malware & Threats 3
Anubis Ransomware ransomware Targets: Coca-Cola subsidiary Fairlife (US)

The Anubis ransomware group listed Coca-Cola dairy production subsidiary Fairlife on its leak website on July 20, 2026, days after Coca-Cola notified the SEC of the initial breach.

Source
Iranian State-Sponsored APTs apt Targets: US critical infrastructure (water, energy facilities)

CISA expanded its alert on Iranian-affiliated hackers attacking US critical infrastructure, including water and energy facilities. Privately owned water utilities remain a soft target lacking basic cybersecurity protections.

Source
Crimson Collective ransomware Targets: Brightspeed telecommunications (US)

New aggressive cyber extortion group claimed to steal data of over 1 million customers of telecommunications provider Brightspeed in a ransomware attack.

Source
Security News 4
Microsoft July 2026 Patch Tuesday Breaks All Records: 570+ CVEs Fixed

Microsoft released its largest Patch Tuesday ever, addressing 570-622 CVEs including 56-63 critical flaws and three zero-days (two actively exploited). CISA ordered federal agencies to patch CVE-2026-56155 and CVE-2026-56164 by July 14.

Read more
CISA Adds Two WordPress Core Vulnerabilities to Known Exploited Vulnerabilities Catalog

CISA added CVE-2026-63030 (wp2shell RCE) and CVE-2026-60137 (SQL injection) to its KEV catalog following active exploitation reports. WordPress sites urged to update immediately.

Read more
North Korea Arrests Former Cyber Elite for Hacking State Banks

North Korea arrested a former elite hacker for allegedly hacking into state banks, in a rare case of the regime prosecuting one of its own cyber operatives.

Read more
Hackers Build Database of 30,000 Working Fortinet Logins

Threat actors have compiled a database of 30,000 valid Fortinet device credentials, posing a significant risk to organizations using Fortinet appliances without proper security configurations.

Read more
23 Jul 2026
Daily Cybersecurity Briefing — July 23, 2026
5 CVEs 4 threats 5 news items
Critical Vulnerabilities 5
CVE-2026-6875 CVSS 9.5 ServiceNow AI Platform

Critical sandbox escape vulnerability in the ServiceNow AI Platform allowing unauthenticated remote code execution. Active exploitation observed in the wild since July 18, 2026. Threat actors escape the script sandbox to execute arbitrary code on the underlying system.

Source
CVE-2025-53770 CVSS 9.8 Microsoft SharePoint Server (on-premises)

Critical deserialization RCE vulnerability in on-premises Microsoft SharePoint Server (ToolShell chain). Allows unauthenticated attackers to execute code over the network. Actively exploited in the wild by Chinese state-sponsored actors, compromising over 75 organizations globally. CISA added to KEV on July 22, 2025.

Source
CVE-2025-20281 CVSS 10.0 Cisco Identity Services Engine (ISE)

Maximum severity unauthenticated remote code execution vulnerability in Cisco ISE and ISE-PIC. Allows an unauthenticated, remote attacker to execute arbitrary commands as root. Actively exploited in attacks since July 2025. CISA added to KEV on July 28, 2025.

Source
CVE-2025-8088 CVSS 7.8 WinRAR (Windows)

Path traversal vulnerability in WinRAR for Windows allowing attackers to execute arbitrary code via crafted malicious archive files. Actively exploited by multiple threat actors including Russia-aligned RomCom group targeting Ukrainian organizations. Exploitation began as early as July 18, 2025 and continues.

Source
CVE-2025-5777 CVSS 8.2 Citrix NetScaler (Citrix Bleed 2)

Session theft vulnerability in Citrix NetScaler ADC and Gateway appliances. Allows attackers to steal authentication sessions and bypass MFA. Actively exploited by ransomware groups including DragonForce and Anubis affiliates to gain initial access to target networks.

Source
Malware & Threats 4
Qilin (Agenda) Ransomware ransomware Targets: Global — critical infrastructure, healthcare, finance

Qilin remains one of the most active ransomware groups in 2026. Now exploiting PAN-OS GlobalProtect vulnerability CVE-2026-0257 as initial access vector to deploy ransomware. Belgium's Centre for Cybersecurity published a threat intelligence report on Qilin today. Known for double extortion tactics.

Source
DragonForce Ransomware ransomware Targets: Global — multiple sectors

DragonForce ransomware group actively exploiting Citrix Bleed 2 (CVE-2025-5777) in a seven-step attack chain. Uses stolen NetScaler sessions to bypass MFA, deploy ransomware via RMM tools, VPN logins, RDP, PsExec, and cloud-transfer tools.

Source
RomCom (APT) / LAMEHUG apt Targets: Ukraine, Europe, Canada

Russia-aligned APT group actively exploiting WinRAR CVE-2025-8088 in targeted attacks against Ukrainian organizations. Campaigns also target companies in Europe and Canada. Uses crafted archive files to deliver malware payloads.

Source
Anubis Affiliates ransomware Targets: Global — healthcare, government, enterprise

Anubis ransomware affiliates exploiting Citrix Bleed 2 (CVE-2025-5777) for session hijacking and MFA bypass. Uses RMM tools, VPN logins, and PsExec for lateral movement before ransomware deployment. Active in initial access broker ecosystem.

Source
Security News 5
Critical ServiceNow AI Platform Flaw (CVE-2026-6875) Under Active Exploitation

ServiceNow disclosed a critical sandbox escape vulnerability (CVE-2026-6875, CVSS 9.5) in its AI Platform. First exploitation attempts detected on July 18, 2026. Unauthenticated attackers can escape the script sandbox and execute remote code. ServiceNow has released patches. Organizations urged to apply updates immediately.

Read more
Five Eyes Nations Warn of Looming AI-Fueled Cyber Threats

The Five Eyes intelligence alliance (US, UK, Canada, Australia, New Zealand) issued a joint warning about AI-fueled cyber attacks. Frontier AI models are enabling sophisticated phishing, deepfake impersonation, and automated vulnerability discovery at scale. Governments urged to prepare for a new generation of AI-powered cyber threats targeting critical infrastructure.

Read more
Ransomware Groups Adopt Citrix Bleed 2, BYOVD, and Supply Chain Attacks

Arctic Wolf reports that ransomware affiliates are increasingly using Citrix Bleed 2 (CVE-2025-5777), BYOVD (Bring Your Own Vulnerable Driver) attacks, and supply chain compromises. DragonForce and Anubis groups lead the trend. Over 96 ransomware attacks were publicly disclosed in July 2025, a 50% year-over-year increase.

Read more
Qilin Ransomware Exploits PAN-OS GlobalProtect Flaw for Initial Access

Qilin ransomware affiliates are actively exploiting CVE-2026-0257, a high-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect VPN. The vulnerability allows unauthorized VPN access to unpatched networks, enabling ransomware deployment. Arctic Wolf Labs investigated multiple intrusions using this vector.

Read more
Ingram Micro Ransomware Attack Impacted 42,000 Individuals

IT distributor Ingram Micro confirmed that a ransomware attack detected on July 3, 2025 resulted in a data breach affecting over 42,000 individuals. The SafePay ransomware group claimed responsibility. Systems were taken offline to contain the attack, causing global operational disruptions.

Read more
22 Jul 2026
Daily Cybersecurity Briefing — July 22, 2026
5 CVEs 2 threats 5 news items
Critical Vulnerabilities 5
CVE-2026-60137 CVSS 9.8 WordPress Core (6.9.0–6.9.4)

Critical unauthenticated SQL injection vulnerability in WordPress REST API. Paired with CVE-2026-63030 as part of the 'wp2shell' exploit chain allowing unauthenticated remote code execution on unpatched WordPress sites.

Source
CVE-2026-63030 CVSS 9.8 WordPress Core (6.9.0–6.9.4)

Critical pre-authentication remote code execution vulnerability in WordPress REST API Batch routing mechanism. Chained with CVE-2026-60137 for full 'wp2shell' unauthenticated RCE. Public exploits released and active exploitation confirmed in the wild.

Source
CVE-2026-14266 CVSS 8.8 7-Zip (XZ decoder)

High-severity heap overflow vulnerability in 7-Zip's XZ archive decoder. A crafted XZ archive can trigger remote code execution when opened by the user. Affects all versions before the patched release.

Source
CVE-2026-58644 CVSS 9.8 Microsoft SharePoint Server 2016 / Enterprise Server 2016

Critical deserialization of untrusted data vulnerability in Microsoft SharePoint Server that allows network-based remote code execution. Requires at least Site Owner privileges. Patched in Microsoft's July 2026 Patch Tuesday.

Source
CVE-2026-57092 CVSS 9.9 Microsoft Windows VMSwitch

Critical elevation of privilege (EoP) vulnerability in Microsoft Windows VMSwitch. A use-after-free flaw rated CVSS 9.9. Allows an attacker to gain elevated privileges on Hyper-V hosts. Part of the record-breaking July 2026 Patch Tuesday.

Source
Malware & Threats 2
JADEPUFFER ransomware Targets: Global organizations

Newly identified AI-driven autonomous ransomware strain. Uses machine learning to intelligently identify critical files and evade detection. First observed in late June/early July 2026. Threat actors are leveraging AI to automate and accelerate ransomware attacks.

Source
SideWinder APT (Rattlesnake) apt Targets: Government and military entities in South Asia

Active APT group targeting government entities. New IOCs and infrastructure detected in July 2026. Known for spear-phishing campaigns and custom malware tooling.

Source
Security News 5
Microsoft Patches Record 622 Flaws in July 2026 Patch Tuesday, Including Three Zero-Days

Microsoft released security updates for a record-breaking 622 vulnerabilities across its product ecosystem. The update includes fixes for two actively exploited zero-days and one publicly disclosed zero-day. Among the most critical are CVE-2026-57092 (CVSS 9.9 VMSwitch EoP) and CVE-2026-58644 (CVSS 9.8 SharePoint RCE). Organizations are urged to patch immediately.

Read more
Russian Intelligence Hijacks IP Cameras Across Europe to Spy on Military Logistics

At least one Russian intelligence service is systematically compromising internet-connected security cameras across Europe and Ukraine. The hijacked feeds are used to track military transport routes, weapons shipments to Kyiv, and troop movements. Automated image recognition is deployed to identify targets of interest. Dutch intelligence agencies issued warnings about the widespread operation.

Read more
WP2Shell WordPress Vulnerabilities Actively Exploited in the Wild

Two critical WordPress core vulnerabilities (CVE-2026-60137 and CVE-2026-63030), collectively dubbed 'WP2Shell,' are being actively exploited after public exploit code was released. The chain allows unauthenticated remote code execution on WordPress 6.9.0 through 6.9.4. WordPress has released an emergency security update. Over 1 million sites are estimated to be at risk.

Read more
7-Zip Critical Heap Overflow Vulnerability Disclosed

A high-severity heap overflow vulnerability (CVE-2026-14266, CVSS 8.8) was disclosed in 7-Zip's XZ archive decoder. Opening a specially crafted XZ archive can lead to code execution. Users are advised to update 7-Zip to the latest version immediately.

Read more
Autonomous AI Ransomware Emerges as Key Threat in July 2026

Security researchers at Hornetsecurity report a rise in autonomous ransomware strains that use AI to independently identify targets, deploy encryption, and evade defenses. The trend marks a significant evolution in ransomware capabilities, reducing the need for human operators.

Read more
21 Jul 2026
Daily Cybersecurity Briefing — July 21, 2026
7 CVEs 4 threats 5 news items
Critical Vulnerabilities 7
CVE-2026-15409 CVSS 10.0 SonicWall SMA 1000 Series

Critical unauthenticated server-side request forgery (SSRF) vulnerability in SonicWall SMA 1000 series remote access appliances. Allows a remote unauthenticated attacker to force the appliance to make requests to internal resources, potentially leading to full compromise. Actively exploited in the wild since June 22, 2026 by threat actor UTA0533.

Source
CVE-2026-57092 CVSS 9.9 Microsoft Windows VMSwitch

Critical use-after-free vulnerability (CWE-416) in Microsoft Windows VMSwitch that allows an authenticated attacker to elevate privileges over a network with low attack complexity. Part of the record-breaking July 2026 Patch Tuesday release.

Source
CVE-2026-63030 (wp2shell) CVSS 9.8 WordPress Core

Critical unauthenticated remote code execution vulnerability in WordPress core affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1. Chains a REST API batch endpoint route confusion issue with an SQL injection (CVE-2026-60137) allowing unauthenticated attackers to execute arbitrary code on default WordPress installations. Patched in WordPress 6.9.5 and 7.0.2.

Source
CVE-2026-60137 CVSS 9.8 WordPress Core

Unauthenticated SQL injection vulnerability in WordPress core via the author__not_in parameter in WP_Query. Affects WordPress 6.8.0-6.8.5, 6.9.0-6.9.4, and 7.0.0-7.0.1. Used as a vector in the wp2shell attack chain to achieve pre-auth RCE.

Source
CVE-2026-55040 CVSS 9.1 Microsoft SharePoint Server

Critical security feature bypass vulnerability in Microsoft SharePoint Server allowing remote unauthenticated attackers to bypass authentication. Enables an attacker to access and modify sensitive data without valid credentials.

Source
CVE-2026-56155 CVSS 7.8 Microsoft Active Directory Federation Services (AD FS)

Elevation of privilege vulnerability in Active Directory Federation Services that is being actively exploited in the wild. Allows a local attacker to gain administrator privileges on the AD FS host. Added to CISA KEV catalog on July 14, 2026.

Source
CVE-2026-56164 CVSS 7.5 Microsoft SharePoint Server (On-Premises)

Missing authentication for critical function vulnerability in on-premises Microsoft SharePoint Server. Remotely exploitable with low complexity and actively exploited in the wild. Added to CISA KEV catalog on July 14, 2026.

Source
Malware & Threats 4
GodDamn Ransomware ransomware Targets: Windows enterprise environments globally

New GodDamn ransomware family employs the PoisonX kernel driver to neutralize endpoint security software as part of its defense evasion strategy. This is the third iteration from the Hyadina developers, previously known as Monster (2022) and Beast (2024). The malicious driver was Microsoft-signed, allowing it to bypass EDR protections and terminate security processes before encryption.

Source
OkoBot infostealer Targets: Global victims, cryptocurrency holders

Newly identified OkoBot malware framework that deploys over 20 distinct payloads to steal sensitive data and cryptocurrency. Uses modular architecture allowing operators to customize the attack chain per victim.

Source
Vidar Stealer infostealer Targets: US and European Union, Baltic region, NATO entities

Vidar continues as one of the most active info-stealer MaaS operations. Recent campaigns (April-July 2026) involve fake code signing certificates, Go-based loaders, and file inflation techniques. A ClickFix campaign uses compromised WordPress sites with fake CAPTCHA prompts to trick users into infecting themselves with Vidar.

Source
SmartLoader loader Targets: Developers, AI/ML community

Researchers discovered nearly 7,600 malicious GitHub repositories, over 800 of which pose as AI skills or Model Context Protocol (MCP) servers to deliver the SmartLoader malware. Targets the developer community through social engineering on the GitHub platform.

Source
Security News 5
Microsoft July 2026 Patch Tuesday Breaks Records with 570+ Fixes and 3 Zero-Days

Microsoft's largest-ever Patch Tuesday addressed between 570 and 622 CVEs (depending on the count methodology), including 56+ critical vulnerabilities and three zero-days. Two zero-days (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint) are actively exploited in the wild. A third zero-day, a BitLocker bypass, allows physical attackers to access encrypted data. CISA added four exploited vulnerabilities to the KEV catalog.

Read more
SonicWall SMA1000 Zero-Days Actively Exploited by Novel Threat Actor UTA0533

Two SonicWall SMA1000 zero-days (CVE-2026-15409, CVSS 10.0; CVE-2026-15410, CVSS 7.2) have been exploited as zero-days since June 22, 2026, before public disclosure. Volexity is tracking the threat actor as UTA0533. SonicWall released patches on July 14 alongside a security advisory. The SSRF flaw scores a perfect 10.0 on the CVSS scale.

Read more
wp2shell: Critical WordPress Core Pre-Auth RCE Patched on July 17

WordPress released emergency patches (6.9.5, 7.0.2) for a critical unauthenticated remote code execution vulnerability chain dubbed 'wp2shell.' The flaw combines a REST API route confusion issue (CVE-2026-63030) with an SQL injection (CVE-2026-60137), allowing anonymous attackers to execute arbitrary code on default WordPress installations. Over half a billion sites were potentially exposed. Active exploitation has been reported.

Read more
CISA Adds Four Exploited Vulnerabilities to KEV Catalog

On July 14-15, 2026, CISA added SonicWall SMA1000 (CVE-2026-15409, CVE-2026-15410), Microsoft AD FS (CVE-2026-56155), and Microsoft SharePoint Server (CVE-2026-56164) to the Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply mitigations by the specified deadlines.

Read more
Ransomware Activity Surges 33% Year-Over-Year in Q2 2026

Check Point Research reports that ransomware incidents increased by 33% compared to Q2 2025, with an average of 2,270 weekly attacks per organization globally. New variants like GodDamn and Spirals demonstrate increasingly sophisticated defense evasion techniques, including kernel driver abuse and rapid encryption (under 24 hours).

Read more
20 Jul 2026
Daily Cybersecurity Briefing — July 20, 2026
5 CVEs 3 threats 5 news items
Critical Vulnerabilities 5
CVE-2026-56164 CVSS 8.8 Microsoft SharePoint Server

Missing authentication for critical function in Microsoft Office SharePoint Server allows an unauthenticated attacker to elevate privileges over a network. Exploited in the wild as a zero-day before Microsoft's July 2026 Patch Tuesday.

Source
CVE-2026-21509 CVSS 9.8 Microsoft Office

Remote code execution vulnerability in Microsoft Office, actively exploited by APT28 (Fancy Bear / UAC-0001) in espionage campaigns targeting European governments and Ukrainian defense supply chains. The exploit uses crafted Office documents that trigger WebDAV downloads and COM hijacking via OneDriveHealth scheduled tasks.

Source
CVE-2026-25089 CVSS 9.8 Fortinet FortiSandbox

OS command injection vulnerability in Fortinet FortiSandbox versions 5.0.0 and earlier. Added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026, confirming active exploitation in the wild. Allows unauthenticated remote attackers to execute arbitrary OS commands.

Source
CVE-2026-39808 CVSS 9.8 Fortinet FortiSandbox

Critical severity vulnerability in Fortinet FortiSandbox. Added alongside CVE-2026-25089 to CISA's KEV catalog on July 16, 2026. Both flaws are being actively targeted by attackers. Patches were released by Fortinet in April and June 2026.

Source
CVE-2026-56155 CVSS 5.3 Microsoft Active Directory Federation Services (AD FS)

Insufficient granularity of access control in AD FS allows an authorized attacker to elevate privileges locally. Exploited in the wild as part of Microsoft's July 2026 Patch Tuesday advisory. Demonstrates that even moderate-severity bugs are being weaponized.

Source
Malware & Threats 3
Spirals ransomware Targets: South Asian IT services companies

New Rust-based ransomware family discovered by Symantec Threat Hunter Team. Conducted a double-extortion attack against an IT services company in South Asia, completing the full intrusion (initial access to data theft and encryption) in under 24 hours. Uses sophisticated anti-analysis techniques. The skill level of operators suggests wider campaigns may follow.

Source
APT28 (Fancy Bear / UAC-0001) apt Targets: European governments, Ukrainian defense supply chain

Russian state-sponsored APT28 exploiting CVE-2026-21509 (Microsoft Office zero-day) in sophisticated multi-stage espionage campaigns. Uses steganography, cloud-based C2 infrastructure abuse (WebDAV, OneDrive), and email-based backdoors. Deploys PRISMEX malware and Covenant C2 framework via COM hijacking and scheduled tasks.

Source
ToddlerShark / Kimsuky apt Targets: South Korean organizations

North Korean APT group Kimsuky (Emerald Sleet, Velvet Chollima) exploiting ScreenConnect vulnerabilities (CVE-2024-1708, CVE-2024-1709) to deploy ToddlerShark malware. Uses spoofed security software installation pages and fake Webex meeting invitations. The malware features modular capabilities for intelligence gathering.

Source
Security News 5
Microsoft Ships Largest Patch Tuesday in History — 622 CVEs, 2 Zero-Days Exploited in the Wild

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities — the largest in company history — including 56 critical-rated flaws. Two zero-days (CVE-2026-56164 in SharePoint and CVE-2026-56155 in AD FS) were confirmed as actively exploited. Of the total, 510 were rated important. Users are urged to prioritize patching the exploited flaws immediately.

Read more
CISA Adds FortiSandbox and SharePoint Bugs to Known Exploited Vulnerabilities Catalog

CISA added four vulnerabilities to its KEV catalog on July 14-16, 2026, including CVE-2026-56164 (Microsoft SharePoint), CVE-2026-25089 and CVE-2026-39808 (Fortinet FortiSandbox), and CVE-2026-56155 (Microsoft AD FS). Federal agencies are required to apply mitigations by the specified deadlines under BOD 22-01.

Read more
Lidl Confirms Data Breach After Third-Party IT Provider Hack

German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that their personal data — including names, phone numbers, email addresses, and dates of birth — was stolen after attackers breached a third-party IT service provider. The breach highlights ongoing supply chain security risks.

Read more
Spirals Ransomware: New Family Encrypts Networks in Under 24 Hours

A previously unseen ransomware family named 'Spirals' was deployed in a double-extortion attack against an Asian IT services company. Written in Rust, it completed the entire intrusion lifecycle from initial access to data exfiltration and encryption in less than 24 hours. Symantec warns the operators' sophistication suggests imminent wider campaigns.

Read more
APT28 Launches Stealthy Multi-Stage Campaign Using Microsoft Office Zero-Day

Russian state-sponsored group APT28 has been observed using CVE-2026-21509 in a sophisticated espionage campaign targeting European defense supply chains. The attack chain involves malicious Office documents, WebDAV downloads, COM hijacking via OneDriveHealth task, and Covenant C2 deployment. Trellix researchers detail the use of steganography and cloud infrastructure abuse.

Read more
17 Jul 2026
Daily Cybersecurity Briefing — July 17, 2026
5 CVEs 3 threats 5 news items
Critical Vulnerabilities 5
CVE-2026-56155 CVSS 7.8 Microsoft Active Directory Federation Services (AD FS)

An elevation of privilege vulnerability in Microsoft AD FS due to insufficient granularity of access control in DKM container permissions. Actively exploited in the wild as a zero-day. Part of Microsoft's record July 2026 Patch Tuesday addressing 570+ flaws. CISA added to Known Exploited Vulnerabilities catalog.

Source
CVE-2026-56164 CVSS 5.3 Microsoft SharePoint Server

An elevation of privilege vulnerability in Microsoft SharePoint Server due to missing authentication. Despite a modest CVSS score of 5.3, this is an unauthenticated, network-based privilege escalation actively exploited in the wild as a zero-day. Part of Microsoft's July 2026 Patch Tuesday.

Source
CVE-2026-25089 CVSS 9.8 Fortinet FortiSandbox

Critical OS command injection vulnerability (CWE-78) in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS affecting versions 4.4.0-4.4.8 and 5.0.0-5.0.5. An unauthenticated remote attacker can execute arbitrary OS commands via the web UI. Added to CISA KEV. Being actively exploited alongside CVE-2026-39808 and CVE-2026-39813.

Source
CVE-2026-43503 CVSS 8.8 Linux Kernel

Known as 'DirtyClone', this is a Linux kernel local privilege escalation vulnerability in the networking subsystem (skbuff shared-frag handling). Allows a local unprivileged user to gain root access by exploiting cloned network packets. Working proof-of-concept exploit published by JFrog Security Research. Affects most Linux distributions. Part of the DirtyFrag family.

Source
CVE-2026-46331 CVSS 7.8 Linux Kernel

Known as 'pedit COW', this is a Linux kernel local privilege escalation vulnerability in the act_pedit traffic-control action. An out-of-bounds write in the kernel's packet editing subsystem allows a local unprivileged user to escalate to root by poisoning cached binaries without modifying files on disk. Affects multiple Linux distributions including Ubuntu, Red Hat, and CloudLinux.

Source
Malware & Threats 3
Screening Serpens (UNC1549 / Smoke Sandstorm) apt Targets: Technology sector in Middle East, US, Israel, UAE

Iran-nexus APT group conducting spear-phishing campaigns impersonating a global air carrier and a German model agency. Delivers customized malware variants via archive files. Unit 42 researchers documented active 2026 espionage campaigns targeting technology professionals in Middle Eastern countries, with operational escalation in early 2026.

Source
ClickLock Stealer / PamStealer infostealer Targets: macOS users globally

Newly discovered macOS malware that uses ClickFix social engineering tactics to trick users into revealing their login passwords. Targets users seeking tech help, delivers password validation and cryptocurrency theft. Already targeted at least 100 users. Apple introduced defenses in macOS Tahoe 26.4.

Source
Fairlife Ransomware Attack (Coca-Cola) ransomware Targets: Coca-Cola's Fairlife dairy subsidiary, US

Ransomware attack on Coca-Cola's Fairlife dairy subsidiary discovered July 16, 2026. Unauthorized third-party access to part of fairlife's IT systems forced temporary suspension of all US dairy production operations. SEC filing confirmed operational disruption.

Source
Security News 5
Microsoft July 2026 Patch Tuesday Fixes Record 570+ Flaws, Including 3 Zero-Days

Microsoft released its largest Patch Tuesday ever, addressing over 570 vulnerabilities (56 critical, 510 important). Two zero-days were actively exploited: CVE-2026-56155 (AD FS privilege escalation) and CVE-2026-56164 (SharePoint elevation of privilege). A third zero-day was publicly disclosed. CISA added the exploited flaws to its KEV catalog.

Read more
Progress Software Confirms Zero-Day Behind ShareFile Storage Zone Emergency Shutdown

Progress Software confirmed a high-severity path traversal zero-day vulnerability in ShareFile Storage Zones Controller (versions 5.x and 6.x) forced an emergency shutdown of all on-premises deployments on July 10. All customers were told to disable their Storage Zone Controllers. Patches are being rolled out and accounts were disabled as a precautionary measure.

Read more
Coca-Cola's Fairlife Dairy Subsidiary Halts US Production After Ransomware Attack

The Coca-Cola Company disclosed a ransomware attack on its Fairlife dairy subsidiary on July 16, 2026. The attack disrupted IT systems and forced temporary suspension of all US dairy production. The company filed an SEC disclosure and is working with law enforcement and cybersecurity experts to investigate the incident.

Read more
New ClickLock macOS Malware Traps Users into Revealing Login Passwords

Security researchers discovered a new macOS information-stealing malware dubbed 'ClickLock Stealer' that uses ClickFix-style social engineering. Victims are tricked into running malicious scripts that capture their login passwords and cryptocurrency wallet data. The malware validates stolen passwords before exfiltration. At least 100 users have been targeted.

Read more
Iranian APT Group Screening Serpens Escalates Espionage Operations in 2026

Palo Alto Networks Unit 42 documented active Iranian APT group Screening Serpens conducting sophisticated spear-phishing campaigns targeting technology professionals in the Middle East, US, Israel, and UAE. The group uses fake job postings, model agency impersonation, and air carrier lures to deliver custom malware. Operations have escalated amid heightened geopolitical tensions.

Read more
16 Jul 2026
Daily Cybersecurity Briefing — July 16, 2026
6 CVEs 4 threats 7 news items
Critical Vulnerabilities 6
CVE-2026-57092 CVSS 9.9 Microsoft Windows VMSwitch

Critical use-after-free vulnerability in Microsoft Windows VMSwitch allowing a low-privileged attacker to escalate privileges to full host compromise. This is the highest CVSS score in Microsoft's July 2026 Patch Tuesday.

Source
CVE-2026-46817 CVSS 9.8 Oracle Payments (Oracle E-Business Suite)

Easily exploitable vulnerability allowing unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Active exploitation attempts have been confirmed on honeypots. Affects versions 12.2.3-12.2.15.

Source
CVE-2026-48318 CVSS 9.9 VMware vCenter Server / Cloud Foundation

A path traversal vulnerability in VMware products that could lead to arbitrary code execution. Patched in recent VMware security updates alongside CVE-2026-48322 (CVSS 9.6).

Source
CVE-2026-56155 CVSS 8.0 Microsoft Active Directory Federation Services (AD FS)

Actively exploited zero-day elevation of privilege vulnerability. Insufficient granularity of access control in AD FS allows an authorized attacker to elevate privileges locally. One of two zero-days exploited in the wild addressed in July 2026 Patch Tuesday.

Source
CVE-2026-40138 CVSS 9.8 BeyondTrust Remote Support and Privileged Remote Access

Critical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access, allowing unauthenticated remote attackers to bypass authentication.

Source
CVE-2026-10539 CVSS 9.0 W3 Total Cache (WordPress Plugin)

Unauthenticated arbitrary command execution vulnerability in the W3 Total Cache WordPress plugin. Under certain conditions, allows an unauthenticated attacker to execute unauthorized commands on the affected server.

Source
Malware & Threats 4
Armored Likho (BusySnake Stealer) apt Targets: Government agencies and electric power sector in Russia, Kazakhstan, and Brazil

A previously undocumented APT group using AI-crafted malware and spear-phishing attacks exploiting the patched Windows LNK vulnerability CVE-2025-9491. Deploys modular RATs and information stealers (BusySnake) for cyber espionage. Runs parallel financially motivated attacks against private individuals.

Source
UAT-7810 (LapDogs) — LONGLEASH / DOGLEASH / JARLEASH apt Targets: Internet-facing networking devices globally (Ruckus, ASUS embedded devices)

China-nexus APT actively refining bespoke malware to expand its Operational Relay Box (ORB) network. Hijacks internet-facing networking devices to build a proxy infrastructure for further attacks. Continued development of LONGLEASH, DOGLEASH, and JARLEASH malware strains.

Source
Fake GitHub Repositories (292 repos) — Vidar Infostealer infostealer Targets: Software developers and users searching for legitimate tools on GitHub

A threat actor published hundreds of fake GitHub repositories impersonating legitimate software and security projects. Disguised as Claude Code, OpenClaw, and other popular tools to distribute Vidar information-stealing malware. Also promoted via Bing AI search results.

Source
RoguePlanet / LegacyHive (NightmareEclipse) rat Targets: Windows 10 and Windows 11 users

A proof-of-concept zero-day exploit released by researcher NightmareEclipse hours after Microsoft's July 2026 Patch Tuesday. Allows a standard user to spawn a SYSTEM shell on fully patched Windows 10/11 by racing Microsoft Defender's own file handler (Windows Defender Quarantine privilege escalation).

Source
Security News 7
Microsoft July 2026 Patch Tuesday Fixes Record 570+ Flaws Including 3 Zero-Days

Microsoft released patches for a record-breaking 570+ vulnerabilities (622 according to some counts), including two actively exploited zero-days: CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint Server EoP), plus one publicly disclosed BitLocker bypass (CVE-2026-50661). Critical fixes span Windows VMSwitch, Hyper-V, Secure Kernel Mode, Active Directory Certificate Services, and Office Suite.

Read more
U.S. Treasury Sanctions VPN Provider and Cryptor Seller for First Time Over Ransomware Links

OFAC sanctioned First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller for enabling ransomware operations. This marks the first time the U.S. has sanctioned a VPN service for facilitating ransomware activities, targeting infrastructure that shielded ransomware gangs for over 12 years.

Read more
Firefox, Chrome, Adobe, and VMware Release Critical Security Updates

Multiple vendors released critical security patches: VMware addressed CVE-2026-48318 (CVSS 9.9) and CVE-2026-48322 (CVSS 9.6) in vCenter Server; Chrome updated to version 150.0.7871.124/.125 fixing multiple high-severity flaws; Firefox and Adobe also issued security updates addressing critical vulnerabilities.

Read more
Researcher Drops New Windows Zero-Day PoC Hours After Patch Tuesday

Security researcher NightmareEclipse released 'LegacyHive' (RoguePlanet), a Windows zero-day proof-of-concept exploit that works on fully patched systems. The exploit abuses Microsoft Defender's quarantine mechanism to achieve privilege escalation from standard user to SYSTEM. No patch is currently available.

Read more
SAP July 2026 Patch Day: Critical NetWeaver ABAP Flaw (CVSS 9.9)

SAP released 16 new security notes, 1 GitHub advisory, and 3 updated notes. A critical vulnerability in SAP NetWeaver Application Server ABAP (CVSS 9.9) could expose sensitive data. Patches also address flaws in SAP Approuter and other components.

Read more
CISA Breach: Contractor Leaked Credentials via Personal GitHub Repository

A CISA contractor copied a repository containing passwords and internal data to a personal GitHub account that was set to public. The incident, discovered by GitGuardian, led to a formal investigation. CISA published lessons learned highlighting weak security controls around public code repository usage.

Read more
Dutch RDI Investigates ChipSoft Security After Ransomware Attack

The Dutch Healthcare and Youth Inspectorate (RDI) is investigating the security of ChipSoft, a major healthcare software provider, following a ransomware attack that impacted Dutch healthcare institutions. The investigation focuses on whether ChipSoft met its security obligations under Dutch law.

Read more
15 Jul 2026
Daily Cybersecurity Briefing — July 15, 2026
5 CVEs 4 threats 6 news items
Critical Vulnerabilities 5
CVE-2025-53770 CVSS 9.8 Microsoft SharePoint Server (on-premises)

Critical deserialization of untrusted data vulnerability in on-premises Microsoft SharePoint Server (ToolPane.aspx component). Allows an unauthenticated attacker to execute remote code over a network. Actively exploited in the wild since July 7, 2025, targeting Western government entities. Affects SharePoint Server 2016, 2019, and Subscription Edition.

Source
CVE-2025-61882 CVSS 9.8 Oracle E-Business Suite (BI Publisher)

Critical zero-day vulnerability in Oracle Concurrent Processing / BI Publisher Integration component of Oracle E-Business Suite. Remotely exploitable without authentication. Actively exploited by the Cl0p (Clop) ransomware group in a large-scale extortion campaign targeting Oracle EBS customers globally.

Source
CVE-2025-49695 CVSS 8.4 Microsoft Office

Critical remote code execution vulnerability in Microsoft Office. Allows an attacker with local access to execute arbitrary code on affected systems. Part of Microsoft's July 2025 Patch Tuesday addressing 137 vulnerabilities.

Source
CVE-2025-49719 CVSS 7.5 Microsoft SQL Server

Important information disclosure vulnerability in Microsoft SQL Server due to improper input validation. Publicly disclosed zero-day that allows an unauthorized attacker to disclose information over a network. Part of Microsoft's July 2025 Patch Tuesday.

Source
CVE-2025-49724 CVSS 8.1 Windows Connected Devices Platform Service

Remote code execution vulnerability in the Windows Connected Devices Platform Service. An unauthenticated attacker may exploit this to execute code remotely on affected systems.

Source
Malware & Threats 4
Cl0p (Clop) ransomware Targets: Global — Oracle E-Business Suite customers across multiple sectors

Cl0p ransomware gang is conducting a large-scale extortion campaign exploiting CVE-2025-61882, a critical zero-day in Oracle E-Business Suite (BI Publisher). The group exfiltrates data and demands ransom payments under threat of public disclosure. This campaign follows their established pattern of vulnerability-led mass extortion.

Source
APT28 (Fancy Bear) apt Targets: Western logistics entities, technology companies, critical infrastructure

Russian state-sponsored APT28 (GRU Unit 26165) continues targeting Western logistics and technology companies. CISA and international partners warn of Russian state-sponsored cyber campaigns targeting critical infrastructure. The group also exploits vulnerable routers to enable DNS hijacking operations.

Source
Fire Ant apt Targets: Enterprise virtualization infrastructure, VMware ESXi users globally

Advanced Chinese cyber-espionage group conducting hypervisor-level attacks targeting VMware ESXi, vCenter, and network appliances. Prolonged espionage campaign exploiting VMware flaws to compromise virtualized infrastructure for data exfiltration and persistent access.

Source
Scattered Spider (UNC3944) ransomware Targets: Global — primarily telecommunications, technology, and business services

Financially motivated cybercriminal collective employing social engineering, SIM-swapping, and SaaS account takeovers. Updated CISA advisory (July 2025) highlights new TTPs including data theft for extortion and collaboration with multiple ransomware variants. The group is known for sophisticated phishing and MFA bypass techniques.

Source
Security News 6
Microsoft's July 2025 Patch Tuesday Fixes 137 Flaws Including Actively Exploited Zero-Day

Microsoft released security updates for 137 vulnerabilities across 70 products, including one publicly disclosed zero-day (CVE-2025-49719) in SQL Server and multiple critical RCE flaws in SharePoint, Office, and Windows. The SharePoint vulnerability CVE-2025-53770 (CVSS 9.8) is under active exploitation by multiple threat actors.

Read more
SharePoint Zero-Day (CVE-2025-53770) Actively Exploited Since July 7 Targeting Western Governments

Check Point Research and Microsoft confirmed active exploitation of CVE-2025-53770 in on-premises SharePoint Server since July 7, 2025. Attacks initially targeted an unnamed major Western government. Multiple threat actors, including ransomware groups, are leveraging the vulnerability for initial access.

Read more
Cl0p Ransomware Exploiting Oracle E-Business Suite Zero-Day in Global Extortion Campaign

Oracle confirmed active exploitation of CVE-2025-61882 (CVSS 9.8), a critical zero-day in Oracle E-Business Suite BI Publisher. The Cl0p ransomware group is conducting a widespread extortion campaign, sending mass extortion emails to victims. Google Cloud and Tenable confirmed the campaign's scale.

Read more
Ingram Micro Ransomware Attack Breaches Data of 42,000 Individuals

IT distribution giant Ingram Micro confirmed that a July 2025 ransomware attack led to the compromise of personal information belonging to over 42,000 individuals. The attack disrupted internal systems and resulted in data exfiltration by the threat actors.

Read more
US and Allies Warn of Russian APT28 Attacks on Critical Infrastructure

CISA, FBI, and international partners released a joint advisory warning of Russian state-sponsored cyber campaigns targeting Western logistics entities, technology companies, and critical infrastructure. APT28 continues to evolve tradecraft, including DNS hijacking via compromised routers.

Read more
Chinese APTs Exploited ToolShell Zero-Days Before Patch Became Available

Microsoft reported that Chinese threat actors Linen Typhoon, Violet Typhoon, and Storm-2603 exploited ToolShell zero-day vulnerabilities weeks before patches were released. The attacks targeted telecommunications companies, government agencies, and technology firms across multiple continents.

Read more
14 Jul 2026
Daily Cybersecurity Briefing — July 14, 2026
6 CVEs 4 threats 5 news items
Critical Vulnerabilities 6
CVE-2026-50746 CVSS 10.0 Ubiquiti UniFi Connect Application

Critical command injection vulnerability in UniFi Connect Application (versions 3.4.16 and earlier). A malicious actor with network access and low privileges can exploit improper input validation to achieve remote code execution. Ubiquiti has released patches.

Source
CVE-2026-55255 CVSS 9.9 Langflow

Authorization bypass through insecure direct object reference (IDOR) in Langflow. An authenticated attacker can execute another user's flow by specifying the victim's flow identifier, leading to credential harvesting. Added to CISA KEV catalog after active exploitation observed.

Source
CVE-2026-48939 CVSS 10.0 iCagenda Joomla Extension

Maximum-severity vulnerability in the iCagenda extension for Joomla allowing unauthenticated PHP file upload leading to remote code execution. Exploited as a zero-day in the wild. Added to CISA KEV catalog.

Source
CVE-2026-45659 CVSS 8.8 Microsoft SharePoint Server

Remote code execution vulnerability in on-premises Microsoft SharePoint Server stemming from deserialization of untrusted data. Attackers with low privileges can execute arbitrary code. Actively exploited in the wild, added to CISA KEV catalog.

Source
CVE-2026-33825 CVSS 7.8 Microsoft Windows Defender (BlueHammer)

Local privilege escalation vulnerability in Microsoft Defender due to insufficient granularity of access control. Known as 'BlueHammer', now being exploited by ransomware gangs. Added to CISA KEV catalog.

Source
CVE-2026-50656 CVSS 7.8 Microsoft Defender (RoguePlanet)

Microsoft Defender elevation of privilege (EoP) vulnerability known as 'RoguePlanet' that weaponizes the Defender quarantine mechanism to grant SYSTEM privileges. Patched after June 2026 Patch Tuesday disclosure.

Source
Malware & Threats 4
INC Ransomware ransomware Targets: Global, critical infrastructure including healthcare

INC Ransomware has evolved from a nascent RaaS operation into one of the most prolific cybercrime groups in 2026, claiming more than 830 victims since August 2023. Uses double extortion tactics and targets critical infrastructure sectors globally.

Source
Armored Likho (BusySnake) apt Targets: Government agencies and electric power entities in Russia, Brazil, and Kazakhstan

Advanced persistent threat group using modular RATs and information stealers. Uses phishing, GitHub-hosted payloads, LNK abuse, and Go2Tunnel-based tunneling. Known for AI-generated malware comments and the 'BusySnake' infostealer targeting critical infrastructure.

Source
APT-C-60 (SpyGlace) apt Targets: Japanese organizations

South Korea-aligned APT group escalating attacks on Japanese organizations. Deploys updated SpyGlace malware (versions 3.1.12+) via spear-phishing campaigns abusing GitHub, Proton services, and legitimate cloud platforms for C2 communications.

Source
Russian FSB Center 16 apt Targets: Global critical infrastructure — communications, energy, defense, government sectors

Russian state-sponsored cyber actors (FSB Center 16) continue to exploit vulnerable and poorly configured routers to infiltrate critical infrastructure networks. Joint advisory issued by US and 8 allied nations warning of ongoing decade-long espionage campaign.

Source
Security News 5
US and 8 Allies Issue Joint Warning on Russian FSB Router Attacks Targeting Critical Infrastructure

Cybersecurity agencies from the United States, UK, Canada, Australia, New Zealand, and four European nations issued a joint advisory warning that Russian FSB Center 16 hackers are exploiting vulnerable and poorly configured routers to breach critical infrastructure networks worldwide. The advisory urges organizations to harden router configurations and implement network segmentation.

Read more
CISA Adds Multiple Exploited Vulnerabilities to KEV Catalog

CISA added Langflow (CVE-2026-55255, CVSS 9.9), Microsoft SharePoint Server RCE (CVE-2026-45659, CVSS 8.8), iCagenda (CVE-2026-48939, CVSS 10.0), and Balbooa Forms Joomla extension flaws to its Known Exploited Vulnerabilities catalog. Federal agencies are ordered to patch within two weeks.

Read more
Ubiquiti Patches Max-Severity UniFi OS Flaws

Ubiquiti released security advisories for multiple critical vulnerabilities in UniFi products, led by CVE-2026-50746 (CVSS 10.0) affecting UniFi Connect. The flaw allows command injection via improper input validation. Additional critical flaws affect UniFi Talk and UniFi Access products.

Read more
INC Ransomware Claims 830+ Victims, Rises as Top RaaS Threat in 2026

Research from Acronis and The Hacker News charts INC ransomware's evolution from a small RaaS operation to one of the most active cybercrime groups in 2026. With over 830 victims since 2023, INC uses double extortion and targets healthcare, manufacturing, and critical infrastructure sectors.

Read more
Microsoft Patches 'RoguePlanet' Defender Zero-Day After Disclosure

Microsoft released a security patch for CVE-2026-50656, a Defender zero-day vulnerability known as 'RoguePlanet' disclosed by researcher Nightmare-Eclipse. The flaw allows elevation of privilege to SYSTEM level via the Defender quarantine mechanism, marking the third consecutive month the researcher has timed a zero-day disclosure to Patch Tuesday.

Read more
13 Jul 2026
Daily Cybersecurity Briefing — July 13, 2026
5 CVEs 3 threats 8 news items
Critical Vulnerabilities 5
CVE-2026-50746 CVSS 10.0 Ubiquiti UniFi Connect Application

Critical improper access control vulnerability in UniFi Connect Application (≤ 3.4.16) allowing unauthenticated remote attackers with network access to execute command injection. CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

Source
CVE-2026-13028 CVSS 9.6 Google Chrome (Android)

Critical use-after-free vulnerability in the WebGL component of Google Chrome on Android prior to version 149.0.7827.197. Remote attacker can exploit via crafted HTML page for sandbox escape and RCE.

Source
CVE-2026-42055 CVSS 9.5 NGINX (HTTP/2 & gRPC proxy modules)

Critical heap-based buffer overflow in NGINX's ngx_http_proxy_v2_module and ngx_http_grpc_module. Unauthenticated remote attackers can exploit crafted HTTP/2 requests for DoS or potential code execution.

Source
CVE-2026-42897 CVSS 8.8 Microsoft SharePoint Server

Actively exploited vulnerability in Microsoft SharePoint Server. Added to CISA KEV catalog in June 2026. Allows remote code execution on affected SharePoint Server installations.

Source
CVE-2026-50656 CVSS 8.1 Microsoft Defender (RoguePlanet)

Microsoft Defender path redirection zero-day vulnerability (dubbed 'RoguePlanet') actively exploited in ransomware attacks. Allows attackers to bypass Microsoft Defender protections.

Source
Malware & Threats 3
JadePuffer ransomware Targets: Global — cloud-hosted databases

First documented fully-autonomous AI-driven (agentic) ransomware operation. Discovered by Sysdig TRT. An LLM agent autonomously exploited Langflow (CVE-2025-3248) and Nacos servers for initial access, reconnaissance, credential theft, and ransomware deployment.

Source
Screening Serpens apt Targets: Iranian state-sponsored espionage — global

Iranian APT group tracked by Palo Alto Networks Unit 42. Conducts ongoing 2026 espionage campaigns targeting government, telecom, and technology sectors across the Middle East with continuously refined malware.

Source
Gamaredon apt Targets: Ukraine — government and military

Russian-linked APT group expanding Ukraine attacks with new malware variants and cloud service abuse. Uses living-off-the-land techniques and custom backdoors.

Source
Security News 8
First Fully Autonomous AI Ransomware (JadePuffer) Documented in the Wild

Sysdig documented JadePuffer, the first agentic ransomware where an LLM autonomously executed the full attack chain from initial access to extortion. Marks a new era of AI-driven cybercrime.

Read more
Ubiquiti Patches 25 UniFi Flaws Including Critical CVSS 10.0 Vulnerability

Ubiquiti Security Advisory 066 addresses 25 vulnerabilities. CVE-2026-50746 (CVSS 10.0) in UniFi Connect allows unauthenticated command injection. Also patched: CVE-2026-50747 (CVSS 9.8) in UniFi Talk and CVE-2026-50748 in UniFi OS.

Read more
F5 Patches Critical NGINX HTTP/2 Heap Overflow (CVE-2026-42055)

F5 patched CVE-2026-42055, a critical heap-based buffer overflow in NGINX HTTP/2 proxy and gRPC modules. Crafted HPACK data can trigger RCE or DoS. High-severity CVE-2026-50107 also fixed in NGINX Gateway Fabric.

Read more
Microsoft Patches Actively Exploited Defender Zero-Day 'RoguePlanet'

CVE-2026-50656, a Microsoft Defender path redirection vulnerability dubbed 'RoguePlanet', was exploited in ransomware campaigns before Microsoft released a fix. Added to CISA KEV catalog.

Read more
Signal Introduces Security Warnings Against Social Engineering and Phishing

Signal rolled out new in-app confirmations and warning messages to protect users against social engineering, phishing attacks, and account takeover attempts.

Read more
UK Proposes AI-Powered 'Cyber Shield' for Autonomous National Defense

The UK announced plans for an AI-driven 'Cyber Shield' to autonomously protect national-scale critical infrastructure with real-time ML-based threat detection and automated response.

Read more
Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

Australian cyber authorities warned about a global campaign exploiting unpatched CMS plugins and outdated core installations for initial access and data theft.

Read more
KDDI Data Breach Affects Over 12 Million Customers in Japan

Japanese telecom giant KDDI disclosed a major data breach impacting over 12 million individuals, one of the largest telecom-sector breaches in Japan's history.

Read more
Featured Project

Zero Day Clock

Track Time-to-Exploit across 83,000+ CVEs in real time

Explore live exploit intelligence →