List cybersec
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched ..
10:10 pm, July 19, 2026 Cybersecurity
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public dis..
3:10 pm, July 19, 2026 Cybersecurity
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According t..
3:10 pm, July 19, 2026 Cybersecurity
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
3:10 pm, July 19, 2026 Cybersecurity
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide..
3:10 pm, July 19, 2026 Cybersecurity
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]..
8:10 pm, July 18, 2026 Cybersecurity
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [..
6:10 pm, July 18, 2026 Cybersecurity
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]
3:10 pm, July 18, 2026 Cybersecurity
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies ag..
2:10 pm, July 18, 2026 Cybersecurity
Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also ..
12:10 am, July 18, 2026 Cybersecurity
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress sh..
10:10 pm, July 17, 2026 Cybersecurity
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. ..
9:10 pm, July 17, 2026 Cybersecurity
Abbott Laboratories probes two cyber incidents amid extortion claims
{"priority":"HIGH","cve":"N/A","target":"Abbott Laboratories","threat_actor":"N/A","patch_ready":false,"insight":"Abbott Laboratories investigates two separate cybersecurity incidents involving unauth..
9:10 pm, July 17, 2026 Cybersecurity
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
{ "priority": "HIGH", "cve": "N/A", "target": "Vite frontend tooling", "threat_actor": "ChainVeil", "patch_ready": false, "insight": "Seven malicious Vite npm packages use blockchain C2 to..
8:10 pm, July 17, 2026 Cybersecurity
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
{ "priority": "MEDIUM", "cve": "N/A", "target": "DigiCert", "threat_actor": "GoldenEyeDog", "patch_ready": false, "insight": "GoldenEyeDog subgroup linked to DigiCert breach and code-signi..
6:10 pm, July 17, 2026 Cybersecurity
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with Com..
6:10 pm, July 17, 2026 Cybersecurity
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
{ "priority": "HIGH", "cve": "N/A", "target": "OpenSSL", "threat_actor": "N/A", "patch_ready": false, "insight": "A vulnerability called HollowByte allows unauthenticated attackers to trig..
6:10 pm, July 17, 2026 Cybersecurity
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
{ "priority": "HIGH", "cve": "N/A", "target": "OTTERCOOKIE", "threat_actor": "Contagious Interview", "patch_ready": false, "insight": "North Korean threat actors use steganography in SVG i..
4:10 pm, July 17, 2026 Cybersecurity
Ernst & Young discloses data breach after support system hack
{ "priority": "MEDIUM", "cve": "N/A", "target": "Ernst & Young support system", "threat_actor": "N/A", "patch_ready": false, "insight": "Ernst & Young discloses data breach after support s..
3:10 pm, July 17, 2026 Cybersecurity
Inside the Search for "Clean" Residential Proxies for Carding
{ "priority": "INFO", "cve": "N/A", "target": "N/A", "threat_actor": "N/A", "patch_ready": false, "insight": "Cybercriminals are seeking 'clean' residential proxies to evade modern fraud d..
2:10 pm, July 17, 2026 Cybersecurity
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
{ "priority": "INFO", "cve": "N/A", "target": "N/A", "threat_actor": "N/A", "patch_ready": false, "insight": "Armenia detains Russian tourist Aleksandr Ermakov on a U.S. extradition reques..
12:10 pm, July 17, 2026 Cybersecurity
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acqu..
12:10 pm, July 17, 2026 Cybersecurity
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
{"priority":"MEDIUM","cve":"N/A","target":"Android","threat_actor":"N/A","patch_ready":false,"insight":"The European Commission ordered Google to provide rival AI assistants with equivalent access to ..
12:10 pm, July 17, 2026 Cybersecurity
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
{"priority": "HIGH", "cve": "N/A", "target": "Southeast Asian Governments and Diplomats", "threat_actor": "N/A", "patch_ready": false, "insight": "New GoSerpent Malware targets Southeast Asian governm..
11:10 am, July 17, 2026 Cybersecurity
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
{"priority":"HIGH","cve":"N/A","target":"Microsoft 365","threat_actor":"ACR Stealer","patch_ready":false,"insight":"ACR Stealer infostealer steals browser tokens, Microsoft 365 files using ClickFix lu..
11:10 am, July 17, 2026 Cybersecurity
New Windows LegacyHive zero-day gives hackers admin privileges
{ "priority": "CRITICAL", "cve": "N/A", "target": "Windows", "threat_actor": "Nightmare Eclipse", "patch_ready": false, "insight": "A zero-day exploit called LegacyHive allows attackers to..
11:10 am, July 17, 2026 Cybersecurity
Windows Server 2022 reach end of mainstream support in 90 days
{ "priority": "INFO", "cve": "N/A", "target": "Windows Server 2022", "threat_actor": "N/A", "patch_ready": false, "insight": "Windows Server 2022 will reach its mainstream support end date..
10:10 am, July 17, 2026 Cybersecurity
US charges two over laundering $43 million from investment fraud
{ "priority": "INFO", "cve": "N/A", "target": "N/A", "threat_actor": "N/A", "patch_ready": false, "insight": "US authorities charged two individuals for laundering $43 million from investm..
9:10 am, July 17, 2026 Cybersecurity
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
{ "priority": "CRITICAL", "cve": "CVE-2026-58644", "target": "Microsoft SharePoint Server", "threat_actor": "N/A", "patch_ready": true, "insight": "CISA added a newly patched SharePoint Se..
8:10 am, July 17, 2026 Cybersecurity
CISA urges immediate action on actively exploited Fortinet flaws
{ "priority": "CRITICAL", "cve": "N/A", "target": "Fortinet FortiSandbox", "threat_actor": "N/A", "patch_ready": true, "insight": "CISA urges immediate patching of actively exploited Forti..
7:10 am, July 17, 2026 Cybersecurity
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
2:10 am, July 17, 2026 Cybersecurity
New ClickLock macOS malware traps users into revealing login password
{ "priority": "HIGH", "cve": "N/A", "target": "macOS", "threat_actor": "N/A", "patch_ready": false, "insight": "New ClickLock macOS malware traps users into revealing login password by ter..
10:10 pm, July 16, 2026 Cybersecurity
Coca-Cola says Fairlife ransomware attack halts US dairy production
{ "priority": "HIGH", "cve": "N/A", "target": "Fairlife dairy", "threat_actor": "Unknown", "patch_ready": false, "insight": "Ransomware attack disrupts Fairlife dairy production across the..
9:10 pm, July 16, 2026 Cybersecurity
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access..
8:10 pm, July 16, 2026 Cybersecurity
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
{ "priority": "LOW", "cve": "N/A", "target": "Transport for London", "threat_actor": "Scattered Spider", "patch_ready": false, "insight": "Two hackers sentenced to 5.5 years each for 2024 ..
7:10 pm, July 16, 2026 Cybersecurity
New OkoBot framework deploys 20 payloads to steal data, crypto
{ "priority": "HIGH", "cve": "N/A", "target": "Cryptocurrency wallets", "threat_actor": "OkoBot", "patch_ready": false, "insight": "OkoBot framework delivers 20 payloads to steal sensitive..
7:10 pm, July 16, 2026 Cybersecurity
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someon..
4:10 pm, July 16, 2026 Cybersecurity
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local us..
3:10 pm, July 16, 2026 Cybersecurity
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
{ "priority": "HIGH", "cve": "N/A", "target": "macOS", "threat_actor": "N/A", "patch_ready": false, "insight": "New ClickLock macOS Stealer kills apps every 210ms until victims type their ..
2:10 pm, July 16, 2026 Cybersecurity
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
{"priority":"HIGH","cve":"N/A","target":"TELEPUZ Malware","threat_actor":"N/A","patch_ready":false,"insight":"New TELEPUZ malware spreading via ClickFix to steal data and run commands."}
2:10 pm, July 16, 2026 Cybersecurity
23andMe to pay $18 million in new genetics data breach settlement
{ "priority": "INFO", "cve": "N/A", "target": "23andMe", "threat_actor": "N/A", "patch_ready": false, "insight": "23andMe agrees to $18 million settlement for failing to protect customers'..
2:10 pm, July 16, 2026 Cybersecurity
AI Agents Broke the Security Playbook. Here's What Replaces It.
{ "priority": "INFO", "cve": "N/A", "target": "N/A", "threat_actor": "N/A", "patch_ready": false, "insight": "The article discusses the need for a new approach to security workflows due to..
2:10 pm, July 16, 2026 Cybersecurity
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
{ "priority": "HIGH", "cve": "N/A", "target": "Taiwan manufacturing firm", "threat_actor": "China-linked threat actor", "patch_ready": false, "insight": "Daxin malware resurfaces in Taiwan..
1:10 pm, July 16, 2026 Cybersecurity
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
{ "priority": "HIGH", "cve": "N/A", "target": "AI Agents", "threat_actor": "N/A", "patch_ready": false, "insight": "New data injection attack can manipulate AI agents to perform unintended..
1:10 pm, July 16, 2026 Cybersecurity
20+ Hijacked Government Websites Became an Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware a..
1:10 pm, July 16, 2026 Cybersecurity
Scattered Spider members behind TfL hack get five years in prison
{ "priority": "LOW", "cve": "N/A", "target": "Transport for London (TfL)", "threat_actor": "Scattered Spider", "patch_ready": false, "insight": "Two leading members of Scattered Spider wer..
1:10 pm, July 16, 2026 Cybersecurity
Windows 11 24H2 Home and Pro reach end of support in 90 days
{ "priority": "INFO", "cve": "N/A", "target": "Windows 11 24H2", "threat_actor": "N/A", "patch_ready": false, "insight": "Microsoft announced that Windows 11 24H2 Home and Pro editions wil..
12:10 pm, July 16, 2026 Cybersecurity
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
{ "priority": "CRITICAL", "cve": "N/A", "target": "Shark RV2320EDUS robot vacuum", "threat_actor": "tokay0", "patch_ready": false, "insight": "Unpatched Shark Vacuum flaw allows attackers ..
11:10 am, July 16, 2026 Cybersecurity
AI Can Find Bugs, But Human Knowledge Still Proves Them
{ "priority": "INFO", "cve": "N/A", "target": "N/A", "threat_actor": "N/A", "patch_ready": false, "insight": "AI-assisted tools are enhancing offensive security by speeding up tasks like c..
11:10 am, July 16, 2026 Cybersecurity
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
{"priority":"HIGH","cve":"N/A","target":"WebEx, Zoom","threat_actor":"UAT-11795","patch_ready":false,"insight":"Russian hackers use trojanized WebEx and Zoom apps to deploy Starland RAT malware"}
11:10 am, July 16, 2026 Cybersecurity
