Critical vulnerabilities, active threats, and security news — curated for professionals.
Critical use-after-free (CWE-416) in Windows VMSwitch allows an authenticated attacker to elevate privileges over a network with low attack complexity. Can be exploited to escape a VM boundary and compromise the host system. Part of the record-breaking July 2026 Patch Tuesday.
SourceElevation of privilege vulnerability caused by insufficient access-control granularity. Exploited in the wild as a zero-day before Microsoft released a patch. Allows an authorized attacker to gain elevated privileges locally.
SourceElevation of privilege vulnerability in SharePoint. Exploited in the wild as a zero-day. Attackers are actively targeting on-premises SharePoint servers. Urgent patching recommended.
SourceCritical REST API batch-route confusion vulnerability in WordPress Core that disables an authorization check, allowing unauthenticated attackers to achieve remote code execution. Added to CISA KEV catalog on July 21, 2026.
SourceSQL injection vulnerability in WordPress Core WP_Query component, actively exploited in the wild. Allows unauthenticated attackers to compromise websites and potentially achieve remote code execution when chained with other flaws. Added to CISA KEV.
SourceThe Anubis ransomware group listed Coca-Cola dairy production subsidiary Fairlife on its leak website on July 20, 2026, days after Coca-Cola notified the SEC of the initial breach.
SourceCISA expanded its alert on Iranian-affiliated hackers attacking US critical infrastructure, including water and energy facilities. Privately owned water utilities remain a soft target lacking basic cybersecurity protections.
SourceNew aggressive cyber extortion group claimed to steal data of over 1 million customers of telecommunications provider Brightspeed in a ransomware attack.
SourceMicrosoft released its largest Patch Tuesday ever, addressing 570-622 CVEs including 56-63 critical flaws and three zero-days (two actively exploited). CISA ordered federal agencies to patch CVE-2026-56155 and CVE-2026-56164 by July 14.
Read moreCISA added CVE-2026-63030 (wp2shell RCE) and CVE-2026-60137 (SQL injection) to its KEV catalog following active exploitation reports. WordPress sites urged to update immediately.
Read moreNorth Korea arrested a former elite hacker for allegedly hacking into state banks, in a rare case of the regime prosecuting one of its own cyber operatives.
Read moreThreat actors have compiled a database of 30,000 valid Fortinet device credentials, posing a significant risk to organizations using Fortinet appliances without proper security configurations.
Read moreCritical sandbox escape vulnerability in the ServiceNow AI Platform allowing unauthenticated remote code execution. Active exploitation observed in the wild since July 18, 2026. Threat actors escape the script sandbox to execute arbitrary code on the underlying system.
SourceCritical deserialization RCE vulnerability in on-premises Microsoft SharePoint Server (ToolShell chain). Allows unauthenticated attackers to execute code over the network. Actively exploited in the wild by Chinese state-sponsored actors, compromising over 75 organizations globally. CISA added to KEV on July 22, 2025.
SourceMaximum severity unauthenticated remote code execution vulnerability in Cisco ISE and ISE-PIC. Allows an unauthenticated, remote attacker to execute arbitrary commands as root. Actively exploited in attacks since July 2025. CISA added to KEV on July 28, 2025.
SourcePath traversal vulnerability in WinRAR for Windows allowing attackers to execute arbitrary code via crafted malicious archive files. Actively exploited by multiple threat actors including Russia-aligned RomCom group targeting Ukrainian organizations. Exploitation began as early as July 18, 2025 and continues.
SourceSession theft vulnerability in Citrix NetScaler ADC and Gateway appliances. Allows attackers to steal authentication sessions and bypass MFA. Actively exploited by ransomware groups including DragonForce and Anubis affiliates to gain initial access to target networks.
SourceQilin remains one of the most active ransomware groups in 2026. Now exploiting PAN-OS GlobalProtect vulnerability CVE-2026-0257 as initial access vector to deploy ransomware. Belgium's Centre for Cybersecurity published a threat intelligence report on Qilin today. Known for double extortion tactics.
SourceDragonForce ransomware group actively exploiting Citrix Bleed 2 (CVE-2025-5777) in a seven-step attack chain. Uses stolen NetScaler sessions to bypass MFA, deploy ransomware via RMM tools, VPN logins, RDP, PsExec, and cloud-transfer tools.
SourceRussia-aligned APT group actively exploiting WinRAR CVE-2025-8088 in targeted attacks against Ukrainian organizations. Campaigns also target companies in Europe and Canada. Uses crafted archive files to deliver malware payloads.
SourceAnubis ransomware affiliates exploiting Citrix Bleed 2 (CVE-2025-5777) for session hijacking and MFA bypass. Uses RMM tools, VPN logins, and PsExec for lateral movement before ransomware deployment. Active in initial access broker ecosystem.
SourceServiceNow disclosed a critical sandbox escape vulnerability (CVE-2026-6875, CVSS 9.5) in its AI Platform. First exploitation attempts detected on July 18, 2026. Unauthenticated attackers can escape the script sandbox and execute remote code. ServiceNow has released patches. Organizations urged to apply updates immediately.
Read moreThe Five Eyes intelligence alliance (US, UK, Canada, Australia, New Zealand) issued a joint warning about AI-fueled cyber attacks. Frontier AI models are enabling sophisticated phishing, deepfake impersonation, and automated vulnerability discovery at scale. Governments urged to prepare for a new generation of AI-powered cyber threats targeting critical infrastructure.
Read moreArctic Wolf reports that ransomware affiliates are increasingly using Citrix Bleed 2 (CVE-2025-5777), BYOVD (Bring Your Own Vulnerable Driver) attacks, and supply chain compromises. DragonForce and Anubis groups lead the trend. Over 96 ransomware attacks were publicly disclosed in July 2025, a 50% year-over-year increase.
Read moreQilin ransomware affiliates are actively exploiting CVE-2026-0257, a high-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect VPN. The vulnerability allows unauthorized VPN access to unpatched networks, enabling ransomware deployment. Arctic Wolf Labs investigated multiple intrusions using this vector.
Read moreIT distributor Ingram Micro confirmed that a ransomware attack detected on July 3, 2025 resulted in a data breach affecting over 42,000 individuals. The SafePay ransomware group claimed responsibility. Systems were taken offline to contain the attack, causing global operational disruptions.
Read moreCritical unauthenticated SQL injection vulnerability in WordPress REST API. Paired with CVE-2026-63030 as part of the 'wp2shell' exploit chain allowing unauthenticated remote code execution on unpatched WordPress sites.
SourceCritical pre-authentication remote code execution vulnerability in WordPress REST API Batch routing mechanism. Chained with CVE-2026-60137 for full 'wp2shell' unauthenticated RCE. Public exploits released and active exploitation confirmed in the wild.
SourceHigh-severity heap overflow vulnerability in 7-Zip's XZ archive decoder. A crafted XZ archive can trigger remote code execution when opened by the user. Affects all versions before the patched release.
SourceCritical deserialization of untrusted data vulnerability in Microsoft SharePoint Server that allows network-based remote code execution. Requires at least Site Owner privileges. Patched in Microsoft's July 2026 Patch Tuesday.
SourceCritical elevation of privilege (EoP) vulnerability in Microsoft Windows VMSwitch. A use-after-free flaw rated CVSS 9.9. Allows an attacker to gain elevated privileges on Hyper-V hosts. Part of the record-breaking July 2026 Patch Tuesday.
SourceNewly identified AI-driven autonomous ransomware strain. Uses machine learning to intelligently identify critical files and evade detection. First observed in late June/early July 2026. Threat actors are leveraging AI to automate and accelerate ransomware attacks.
SourceActive APT group targeting government entities. New IOCs and infrastructure detected in July 2026. Known for spear-phishing campaigns and custom malware tooling.
SourceMicrosoft released security updates for a record-breaking 622 vulnerabilities across its product ecosystem. The update includes fixes for two actively exploited zero-days and one publicly disclosed zero-day. Among the most critical are CVE-2026-57092 (CVSS 9.9 VMSwitch EoP) and CVE-2026-58644 (CVSS 9.8 SharePoint RCE). Organizations are urged to patch immediately.
Read moreAt least one Russian intelligence service is systematically compromising internet-connected security cameras across Europe and Ukraine. The hijacked feeds are used to track military transport routes, weapons shipments to Kyiv, and troop movements. Automated image recognition is deployed to identify targets of interest. Dutch intelligence agencies issued warnings about the widespread operation.
Read moreTwo critical WordPress core vulnerabilities (CVE-2026-60137 and CVE-2026-63030), collectively dubbed 'WP2Shell,' are being actively exploited after public exploit code was released. The chain allows unauthenticated remote code execution on WordPress 6.9.0 through 6.9.4. WordPress has released an emergency security update. Over 1 million sites are estimated to be at risk.
Read moreA high-severity heap overflow vulnerability (CVE-2026-14266, CVSS 8.8) was disclosed in 7-Zip's XZ archive decoder. Opening a specially crafted XZ archive can lead to code execution. Users are advised to update 7-Zip to the latest version immediately.
Read moreSecurity researchers at Hornetsecurity report a rise in autonomous ransomware strains that use AI to independently identify targets, deploy encryption, and evade defenses. The trend marks a significant evolution in ransomware capabilities, reducing the need for human operators.
Read moreCritical unauthenticated server-side request forgery (SSRF) vulnerability in SonicWall SMA 1000 series remote access appliances. Allows a remote unauthenticated attacker to force the appliance to make requests to internal resources, potentially leading to full compromise. Actively exploited in the wild since June 22, 2026 by threat actor UTA0533.
SourceCritical use-after-free vulnerability (CWE-416) in Microsoft Windows VMSwitch that allows an authenticated attacker to elevate privileges over a network with low attack complexity. Part of the record-breaking July 2026 Patch Tuesday release.
SourceCritical unauthenticated remote code execution vulnerability in WordPress core affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1. Chains a REST API batch endpoint route confusion issue with an SQL injection (CVE-2026-60137) allowing unauthenticated attackers to execute arbitrary code on default WordPress installations. Patched in WordPress 6.9.5 and 7.0.2.
SourceUnauthenticated SQL injection vulnerability in WordPress core via the author__not_in parameter in WP_Query. Affects WordPress 6.8.0-6.8.5, 6.9.0-6.9.4, and 7.0.0-7.0.1. Used as a vector in the wp2shell attack chain to achieve pre-auth RCE.
SourceCritical security feature bypass vulnerability in Microsoft SharePoint Server allowing remote unauthenticated attackers to bypass authentication. Enables an attacker to access and modify sensitive data without valid credentials.
SourceElevation of privilege vulnerability in Active Directory Federation Services that is being actively exploited in the wild. Allows a local attacker to gain administrator privileges on the AD FS host. Added to CISA KEV catalog on July 14, 2026.
SourceMissing authentication for critical function vulnerability in on-premises Microsoft SharePoint Server. Remotely exploitable with low complexity and actively exploited in the wild. Added to CISA KEV catalog on July 14, 2026.
SourceNew GodDamn ransomware family employs the PoisonX kernel driver to neutralize endpoint security software as part of its defense evasion strategy. This is the third iteration from the Hyadina developers, previously known as Monster (2022) and Beast (2024). The malicious driver was Microsoft-signed, allowing it to bypass EDR protections and terminate security processes before encryption.
SourceNewly identified OkoBot malware framework that deploys over 20 distinct payloads to steal sensitive data and cryptocurrency. Uses modular architecture allowing operators to customize the attack chain per victim.
SourceVidar continues as one of the most active info-stealer MaaS operations. Recent campaigns (April-July 2026) involve fake code signing certificates, Go-based loaders, and file inflation techniques. A ClickFix campaign uses compromised WordPress sites with fake CAPTCHA prompts to trick users into infecting themselves with Vidar.
SourceResearchers discovered nearly 7,600 malicious GitHub repositories, over 800 of which pose as AI skills or Model Context Protocol (MCP) servers to deliver the SmartLoader malware. Targets the developer community through social engineering on the GitHub platform.
SourceMicrosoft's largest-ever Patch Tuesday addressed between 570 and 622 CVEs (depending on the count methodology), including 56+ critical vulnerabilities and three zero-days. Two zero-days (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint) are actively exploited in the wild. A third zero-day, a BitLocker bypass, allows physical attackers to access encrypted data. CISA added four exploited vulnerabilities to the KEV catalog.
Read moreTwo SonicWall SMA1000 zero-days (CVE-2026-15409, CVSS 10.0; CVE-2026-15410, CVSS 7.2) have been exploited as zero-days since June 22, 2026, before public disclosure. Volexity is tracking the threat actor as UTA0533. SonicWall released patches on July 14 alongside a security advisory. The SSRF flaw scores a perfect 10.0 on the CVSS scale.
Read moreWordPress released emergency patches (6.9.5, 7.0.2) for a critical unauthenticated remote code execution vulnerability chain dubbed 'wp2shell.' The flaw combines a REST API route confusion issue (CVE-2026-63030) with an SQL injection (CVE-2026-60137), allowing anonymous attackers to execute arbitrary code on default WordPress installations. Over half a billion sites were potentially exposed. Active exploitation has been reported.
Read moreOn July 14-15, 2026, CISA added SonicWall SMA1000 (CVE-2026-15409, CVE-2026-15410), Microsoft AD FS (CVE-2026-56155), and Microsoft SharePoint Server (CVE-2026-56164) to the Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply mitigations by the specified deadlines.
Read moreCheck Point Research reports that ransomware incidents increased by 33% compared to Q2 2025, with an average of 2,270 weekly attacks per organization globally. New variants like GodDamn and Spirals demonstrate increasingly sophisticated defense evasion techniques, including kernel driver abuse and rapid encryption (under 24 hours).
Read moreMissing authentication for critical function in Microsoft Office SharePoint Server allows an unauthenticated attacker to elevate privileges over a network. Exploited in the wild as a zero-day before Microsoft's July 2026 Patch Tuesday.
SourceRemote code execution vulnerability in Microsoft Office, actively exploited by APT28 (Fancy Bear / UAC-0001) in espionage campaigns targeting European governments and Ukrainian defense supply chains. The exploit uses crafted Office documents that trigger WebDAV downloads and COM hijacking via OneDriveHealth scheduled tasks.
SourceOS command injection vulnerability in Fortinet FortiSandbox versions 5.0.0 and earlier. Added to CISA's Known Exploited Vulnerabilities catalog on July 16, 2026, confirming active exploitation in the wild. Allows unauthenticated remote attackers to execute arbitrary OS commands.
SourceCritical severity vulnerability in Fortinet FortiSandbox. Added alongside CVE-2026-25089 to CISA's KEV catalog on July 16, 2026. Both flaws are being actively targeted by attackers. Patches were released by Fortinet in April and June 2026.
SourceInsufficient granularity of access control in AD FS allows an authorized attacker to elevate privileges locally. Exploited in the wild as part of Microsoft's July 2026 Patch Tuesday advisory. Demonstrates that even moderate-severity bugs are being weaponized.
SourceNew Rust-based ransomware family discovered by Symantec Threat Hunter Team. Conducted a double-extortion attack against an IT services company in South Asia, completing the full intrusion (initial access to data theft and encryption) in under 24 hours. Uses sophisticated anti-analysis techniques. The skill level of operators suggests wider campaigns may follow.
SourceRussian state-sponsored APT28 exploiting CVE-2026-21509 (Microsoft Office zero-day) in sophisticated multi-stage espionage campaigns. Uses steganography, cloud-based C2 infrastructure abuse (WebDAV, OneDrive), and email-based backdoors. Deploys PRISMEX malware and Covenant C2 framework via COM hijacking and scheduled tasks.
SourceNorth Korean APT group Kimsuky (Emerald Sleet, Velvet Chollima) exploiting ScreenConnect vulnerabilities (CVE-2024-1708, CVE-2024-1709) to deploy ToddlerShark malware. Uses spoofed security software installation pages and fake Webex meeting invitations. The malware features modular capabilities for intelligence gathering.
SourceMicrosoft's July 2026 Patch Tuesday addressed 622 vulnerabilities — the largest in company history — including 56 critical-rated flaws. Two zero-days (CVE-2026-56164 in SharePoint and CVE-2026-56155 in AD FS) were confirmed as actively exploited. Of the total, 510 were rated important. Users are urged to prioritize patching the exploited flaws immediately.
Read moreCISA added four vulnerabilities to its KEV catalog on July 14-16, 2026, including CVE-2026-56164 (Microsoft SharePoint), CVE-2026-25089 and CVE-2026-39808 (Fortinet FortiSandbox), and CVE-2026-56155 (Microsoft AD FS). Federal agencies are required to apply mitigations by the specified deadlines under BOD 22-01.
Read moreGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that their personal data — including names, phone numbers, email addresses, and dates of birth — was stolen after attackers breached a third-party IT service provider. The breach highlights ongoing supply chain security risks.
Read moreA previously unseen ransomware family named 'Spirals' was deployed in a double-extortion attack against an Asian IT services company. Written in Rust, it completed the entire intrusion lifecycle from initial access to data exfiltration and encryption in less than 24 hours. Symantec warns the operators' sophistication suggests imminent wider campaigns.
Read moreRussian state-sponsored group APT28 has been observed using CVE-2026-21509 in a sophisticated espionage campaign targeting European defense supply chains. The attack chain involves malicious Office documents, WebDAV downloads, COM hijacking via OneDriveHealth task, and Covenant C2 deployment. Trellix researchers detail the use of steganography and cloud infrastructure abuse.
Read moreAn elevation of privilege vulnerability in Microsoft AD FS due to insufficient granularity of access control in DKM container permissions. Actively exploited in the wild as a zero-day. Part of Microsoft's record July 2026 Patch Tuesday addressing 570+ flaws. CISA added to Known Exploited Vulnerabilities catalog.
SourceAn elevation of privilege vulnerability in Microsoft SharePoint Server due to missing authentication. Despite a modest CVSS score of 5.3, this is an unauthenticated, network-based privilege escalation actively exploited in the wild as a zero-day. Part of Microsoft's July 2026 Patch Tuesday.
SourceCritical OS command injection vulnerability (CWE-78) in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS affecting versions 4.4.0-4.4.8 and 5.0.0-5.0.5. An unauthenticated remote attacker can execute arbitrary OS commands via the web UI. Added to CISA KEV. Being actively exploited alongside CVE-2026-39808 and CVE-2026-39813.
SourceKnown as 'DirtyClone', this is a Linux kernel local privilege escalation vulnerability in the networking subsystem (skbuff shared-frag handling). Allows a local unprivileged user to gain root access by exploiting cloned network packets. Working proof-of-concept exploit published by JFrog Security Research. Affects most Linux distributions. Part of the DirtyFrag family.
SourceKnown as 'pedit COW', this is a Linux kernel local privilege escalation vulnerability in the act_pedit traffic-control action. An out-of-bounds write in the kernel's packet editing subsystem allows a local unprivileged user to escalate to root by poisoning cached binaries without modifying files on disk. Affects multiple Linux distributions including Ubuntu, Red Hat, and CloudLinux.
SourceIran-nexus APT group conducting spear-phishing campaigns impersonating a global air carrier and a German model agency. Delivers customized malware variants via archive files. Unit 42 researchers documented active 2026 espionage campaigns targeting technology professionals in Middle Eastern countries, with operational escalation in early 2026.
SourceNewly discovered macOS malware that uses ClickFix social engineering tactics to trick users into revealing their login passwords. Targets users seeking tech help, delivers password validation and cryptocurrency theft. Already targeted at least 100 users. Apple introduced defenses in macOS Tahoe 26.4.
SourceRansomware attack on Coca-Cola's Fairlife dairy subsidiary discovered July 16, 2026. Unauthorized third-party access to part of fairlife's IT systems forced temporary suspension of all US dairy production operations. SEC filing confirmed operational disruption.
SourceMicrosoft released its largest Patch Tuesday ever, addressing over 570 vulnerabilities (56 critical, 510 important). Two zero-days were actively exploited: CVE-2026-56155 (AD FS privilege escalation) and CVE-2026-56164 (SharePoint elevation of privilege). A third zero-day was publicly disclosed. CISA added the exploited flaws to its KEV catalog.
Read moreProgress Software confirmed a high-severity path traversal zero-day vulnerability in ShareFile Storage Zones Controller (versions 5.x and 6.x) forced an emergency shutdown of all on-premises deployments on July 10. All customers were told to disable their Storage Zone Controllers. Patches are being rolled out and accounts were disabled as a precautionary measure.
Read moreThe Coca-Cola Company disclosed a ransomware attack on its Fairlife dairy subsidiary on July 16, 2026. The attack disrupted IT systems and forced temporary suspension of all US dairy production. The company filed an SEC disclosure and is working with law enforcement and cybersecurity experts to investigate the incident.
Read moreSecurity researchers discovered a new macOS information-stealing malware dubbed 'ClickLock Stealer' that uses ClickFix-style social engineering. Victims are tricked into running malicious scripts that capture their login passwords and cryptocurrency wallet data. The malware validates stolen passwords before exfiltration. At least 100 users have been targeted.
Read morePalo Alto Networks Unit 42 documented active Iranian APT group Screening Serpens conducting sophisticated spear-phishing campaigns targeting technology professionals in the Middle East, US, Israel, and UAE. The group uses fake job postings, model agency impersonation, and air carrier lures to deliver custom malware. Operations have escalated amid heightened geopolitical tensions.
Read moreCritical use-after-free vulnerability in Microsoft Windows VMSwitch allowing a low-privileged attacker to escalate privileges to full host compromise. This is the highest CVSS score in Microsoft's July 2026 Patch Tuesday.
SourceEasily exploitable vulnerability allowing unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Active exploitation attempts have been confirmed on honeypots. Affects versions 12.2.3-12.2.15.
SourceA path traversal vulnerability in VMware products that could lead to arbitrary code execution. Patched in recent VMware security updates alongside CVE-2026-48322 (CVSS 9.6).
SourceActively exploited zero-day elevation of privilege vulnerability. Insufficient granularity of access control in AD FS allows an authorized attacker to elevate privileges locally. One of two zero-days exploited in the wild addressed in July 2026 Patch Tuesday.
SourceCritical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access, allowing unauthenticated remote attackers to bypass authentication.
SourceUnauthenticated arbitrary command execution vulnerability in the W3 Total Cache WordPress plugin. Under certain conditions, allows an unauthenticated attacker to execute unauthorized commands on the affected server.
SourceA previously undocumented APT group using AI-crafted malware and spear-phishing attacks exploiting the patched Windows LNK vulnerability CVE-2025-9491. Deploys modular RATs and information stealers (BusySnake) for cyber espionage. Runs parallel financially motivated attacks against private individuals.
SourceChina-nexus APT actively refining bespoke malware to expand its Operational Relay Box (ORB) network. Hijacks internet-facing networking devices to build a proxy infrastructure for further attacks. Continued development of LONGLEASH, DOGLEASH, and JARLEASH malware strains.
SourceA threat actor published hundreds of fake GitHub repositories impersonating legitimate software and security projects. Disguised as Claude Code, OpenClaw, and other popular tools to distribute Vidar information-stealing malware. Also promoted via Bing AI search results.
SourceA proof-of-concept zero-day exploit released by researcher NightmareEclipse hours after Microsoft's July 2026 Patch Tuesday. Allows a standard user to spawn a SYSTEM shell on fully patched Windows 10/11 by racing Microsoft Defender's own file handler (Windows Defender Quarantine privilege escalation).
SourceMicrosoft released patches for a record-breaking 570+ vulnerabilities (622 according to some counts), including two actively exploited zero-days: CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint Server EoP), plus one publicly disclosed BitLocker bypass (CVE-2026-50661). Critical fixes span Windows VMSwitch, Hyper-V, Secure Kernel Mode, Active Directory Certificate Services, and Office Suite.
Read moreOFAC sanctioned First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller for enabling ransomware operations. This marks the first time the U.S. has sanctioned a VPN service for facilitating ransomware activities, targeting infrastructure that shielded ransomware gangs for over 12 years.
Read moreMultiple vendors released critical security patches: VMware addressed CVE-2026-48318 (CVSS 9.9) and CVE-2026-48322 (CVSS 9.6) in vCenter Server; Chrome updated to version 150.0.7871.124/.125 fixing multiple high-severity flaws; Firefox and Adobe also issued security updates addressing critical vulnerabilities.
Read moreSecurity researcher NightmareEclipse released 'LegacyHive' (RoguePlanet), a Windows zero-day proof-of-concept exploit that works on fully patched systems. The exploit abuses Microsoft Defender's quarantine mechanism to achieve privilege escalation from standard user to SYSTEM. No patch is currently available.
Read moreSAP released 16 new security notes, 1 GitHub advisory, and 3 updated notes. A critical vulnerability in SAP NetWeaver Application Server ABAP (CVSS 9.9) could expose sensitive data. Patches also address flaws in SAP Approuter and other components.
Read moreA CISA contractor copied a repository containing passwords and internal data to a personal GitHub account that was set to public. The incident, discovered by GitGuardian, led to a formal investigation. CISA published lessons learned highlighting weak security controls around public code repository usage.
Read moreThe Dutch Healthcare and Youth Inspectorate (RDI) is investigating the security of ChipSoft, a major healthcare software provider, following a ransomware attack that impacted Dutch healthcare institutions. The investigation focuses on whether ChipSoft met its security obligations under Dutch law.
Read moreCritical deserialization of untrusted data vulnerability in on-premises Microsoft SharePoint Server (ToolPane.aspx component). Allows an unauthenticated attacker to execute remote code over a network. Actively exploited in the wild since July 7, 2025, targeting Western government entities. Affects SharePoint Server 2016, 2019, and Subscription Edition.
SourceCritical zero-day vulnerability in Oracle Concurrent Processing / BI Publisher Integration component of Oracle E-Business Suite. Remotely exploitable without authentication. Actively exploited by the Cl0p (Clop) ransomware group in a large-scale extortion campaign targeting Oracle EBS customers globally.
SourceCritical remote code execution vulnerability in Microsoft Office. Allows an attacker with local access to execute arbitrary code on affected systems. Part of Microsoft's July 2025 Patch Tuesday addressing 137 vulnerabilities.
SourceImportant information disclosure vulnerability in Microsoft SQL Server due to improper input validation. Publicly disclosed zero-day that allows an unauthorized attacker to disclose information over a network. Part of Microsoft's July 2025 Patch Tuesday.
SourceRemote code execution vulnerability in the Windows Connected Devices Platform Service. An unauthenticated attacker may exploit this to execute code remotely on affected systems.
SourceCl0p ransomware gang is conducting a large-scale extortion campaign exploiting CVE-2025-61882, a critical zero-day in Oracle E-Business Suite (BI Publisher). The group exfiltrates data and demands ransom payments under threat of public disclosure. This campaign follows their established pattern of vulnerability-led mass extortion.
SourceRussian state-sponsored APT28 (GRU Unit 26165) continues targeting Western logistics and technology companies. CISA and international partners warn of Russian state-sponsored cyber campaigns targeting critical infrastructure. The group also exploits vulnerable routers to enable DNS hijacking operations.
SourceAdvanced Chinese cyber-espionage group conducting hypervisor-level attacks targeting VMware ESXi, vCenter, and network appliances. Prolonged espionage campaign exploiting VMware flaws to compromise virtualized infrastructure for data exfiltration and persistent access.
SourceFinancially motivated cybercriminal collective employing social engineering, SIM-swapping, and SaaS account takeovers. Updated CISA advisory (July 2025) highlights new TTPs including data theft for extortion and collaboration with multiple ransomware variants. The group is known for sophisticated phishing and MFA bypass techniques.
SourceMicrosoft released security updates for 137 vulnerabilities across 70 products, including one publicly disclosed zero-day (CVE-2025-49719) in SQL Server and multiple critical RCE flaws in SharePoint, Office, and Windows. The SharePoint vulnerability CVE-2025-53770 (CVSS 9.8) is under active exploitation by multiple threat actors.
Read moreCheck Point Research and Microsoft confirmed active exploitation of CVE-2025-53770 in on-premises SharePoint Server since July 7, 2025. Attacks initially targeted an unnamed major Western government. Multiple threat actors, including ransomware groups, are leveraging the vulnerability for initial access.
Read moreOracle confirmed active exploitation of CVE-2025-61882 (CVSS 9.8), a critical zero-day in Oracle E-Business Suite BI Publisher. The Cl0p ransomware group is conducting a widespread extortion campaign, sending mass extortion emails to victims. Google Cloud and Tenable confirmed the campaign's scale.
Read moreIT distribution giant Ingram Micro confirmed that a July 2025 ransomware attack led to the compromise of personal information belonging to over 42,000 individuals. The attack disrupted internal systems and resulted in data exfiltration by the threat actors.
Read moreCISA, FBI, and international partners released a joint advisory warning of Russian state-sponsored cyber campaigns targeting Western logistics entities, technology companies, and critical infrastructure. APT28 continues to evolve tradecraft, including DNS hijacking via compromised routers.
Read moreMicrosoft reported that Chinese threat actors Linen Typhoon, Violet Typhoon, and Storm-2603 exploited ToolShell zero-day vulnerabilities weeks before patches were released. The attacks targeted telecommunications companies, government agencies, and technology firms across multiple continents.
Read moreCritical command injection vulnerability in UniFi Connect Application (versions 3.4.16 and earlier). A malicious actor with network access and low privileges can exploit improper input validation to achieve remote code execution. Ubiquiti has released patches.
SourceAuthorization bypass through insecure direct object reference (IDOR) in Langflow. An authenticated attacker can execute another user's flow by specifying the victim's flow identifier, leading to credential harvesting. Added to CISA KEV catalog after active exploitation observed.
SourceMaximum-severity vulnerability in the iCagenda extension for Joomla allowing unauthenticated PHP file upload leading to remote code execution. Exploited as a zero-day in the wild. Added to CISA KEV catalog.
SourceRemote code execution vulnerability in on-premises Microsoft SharePoint Server stemming from deserialization of untrusted data. Attackers with low privileges can execute arbitrary code. Actively exploited in the wild, added to CISA KEV catalog.
SourceLocal privilege escalation vulnerability in Microsoft Defender due to insufficient granularity of access control. Known as 'BlueHammer', now being exploited by ransomware gangs. Added to CISA KEV catalog.
SourceMicrosoft Defender elevation of privilege (EoP) vulnerability known as 'RoguePlanet' that weaponizes the Defender quarantine mechanism to grant SYSTEM privileges. Patched after June 2026 Patch Tuesday disclosure.
SourceINC Ransomware has evolved from a nascent RaaS operation into one of the most prolific cybercrime groups in 2026, claiming more than 830 victims since August 2023. Uses double extortion tactics and targets critical infrastructure sectors globally.
SourceAdvanced persistent threat group using modular RATs and information stealers. Uses phishing, GitHub-hosted payloads, LNK abuse, and Go2Tunnel-based tunneling. Known for AI-generated malware comments and the 'BusySnake' infostealer targeting critical infrastructure.
SourceSouth Korea-aligned APT group escalating attacks on Japanese organizations. Deploys updated SpyGlace malware (versions 3.1.12+) via spear-phishing campaigns abusing GitHub, Proton services, and legitimate cloud platforms for C2 communications.
SourceRussian state-sponsored cyber actors (FSB Center 16) continue to exploit vulnerable and poorly configured routers to infiltrate critical infrastructure networks. Joint advisory issued by US and 8 allied nations warning of ongoing decade-long espionage campaign.
SourceCybersecurity agencies from the United States, UK, Canada, Australia, New Zealand, and four European nations issued a joint advisory warning that Russian FSB Center 16 hackers are exploiting vulnerable and poorly configured routers to breach critical infrastructure networks worldwide. The advisory urges organizations to harden router configurations and implement network segmentation.
Read moreCISA added Langflow (CVE-2026-55255, CVSS 9.9), Microsoft SharePoint Server RCE (CVE-2026-45659, CVSS 8.8), iCagenda (CVE-2026-48939, CVSS 10.0), and Balbooa Forms Joomla extension flaws to its Known Exploited Vulnerabilities catalog. Federal agencies are ordered to patch within two weeks.
Read moreUbiquiti released security advisories for multiple critical vulnerabilities in UniFi products, led by CVE-2026-50746 (CVSS 10.0) affecting UniFi Connect. The flaw allows command injection via improper input validation. Additional critical flaws affect UniFi Talk and UniFi Access products.
Read moreResearch from Acronis and The Hacker News charts INC ransomware's evolution from a small RaaS operation to one of the most active cybercrime groups in 2026. With over 830 victims since 2023, INC uses double extortion and targets healthcare, manufacturing, and critical infrastructure sectors.
Read moreMicrosoft released a security patch for CVE-2026-50656, a Defender zero-day vulnerability known as 'RoguePlanet' disclosed by researcher Nightmare-Eclipse. The flaw allows elevation of privilege to SYSTEM level via the Defender quarantine mechanism, marking the third consecutive month the researcher has timed a zero-day disclosure to Patch Tuesday.
Read moreCritical improper access control vulnerability in UniFi Connect Application (≤ 3.4.16) allowing unauthenticated remote attackers with network access to execute command injection. CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
SourceCritical use-after-free vulnerability in the WebGL component of Google Chrome on Android prior to version 149.0.7827.197. Remote attacker can exploit via crafted HTML page for sandbox escape and RCE.
SourceCritical heap-based buffer overflow in NGINX's ngx_http_proxy_v2_module and ngx_http_grpc_module. Unauthenticated remote attackers can exploit crafted HTTP/2 requests for DoS or potential code execution.
SourceActively exploited vulnerability in Microsoft SharePoint Server. Added to CISA KEV catalog in June 2026. Allows remote code execution on affected SharePoint Server installations.
SourceMicrosoft Defender path redirection zero-day vulnerability (dubbed 'RoguePlanet') actively exploited in ransomware attacks. Allows attackers to bypass Microsoft Defender protections.
SourceFirst documented fully-autonomous AI-driven (agentic) ransomware operation. Discovered by Sysdig TRT. An LLM agent autonomously exploited Langflow (CVE-2025-3248) and Nacos servers for initial access, reconnaissance, credential theft, and ransomware deployment.
SourceIranian APT group tracked by Palo Alto Networks Unit 42. Conducts ongoing 2026 espionage campaigns targeting government, telecom, and technology sectors across the Middle East with continuously refined malware.
SourceRussian-linked APT group expanding Ukraine attacks with new malware variants and cloud service abuse. Uses living-off-the-land techniques and custom backdoors.
SourceSysdig documented JadePuffer, the first agentic ransomware where an LLM autonomously executed the full attack chain from initial access to extortion. Marks a new era of AI-driven cybercrime.
Read moreUbiquiti Security Advisory 066 addresses 25 vulnerabilities. CVE-2026-50746 (CVSS 10.0) in UniFi Connect allows unauthenticated command injection. Also patched: CVE-2026-50747 (CVSS 9.8) in UniFi Talk and CVE-2026-50748 in UniFi OS.
Read moreF5 patched CVE-2026-42055, a critical heap-based buffer overflow in NGINX HTTP/2 proxy and gRPC modules. Crafted HPACK data can trigger RCE or DoS. High-severity CVE-2026-50107 also fixed in NGINX Gateway Fabric.
Read moreCVE-2026-50656, a Microsoft Defender path redirection vulnerability dubbed 'RoguePlanet', was exploited in ransomware campaigns before Microsoft released a fix. Added to CISA KEV catalog.
Read moreSignal rolled out new in-app confirmations and warning messages to protect users against social engineering, phishing attacks, and account takeover attempts.
Read moreThe UK announced plans for an AI-driven 'Cyber Shield' to autonomously protect national-scale critical infrastructure with real-time ML-based threat detection and automated response.
Read moreAustralian cyber authorities warned about a global campaign exploiting unpatched CMS plugins and outdated core installations for initial access and data theft.
Read moreJapanese telecom giant KDDI disclosed a major data breach impacting over 12 million individuals, one of the largest telecom-sector breaches in Japan's history.
Read more