all—News
Top News
CISA orders feds to patch actively exploited Oracle flaw by Saturday
July 16, 2026Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
July 14, 2026CISA warns admins to patch actively exploited SharePoint flaws
July 15, 2026Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
July 15, 2026CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
July 17, 2026OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
July 17, 2026Latest News
- // no coverAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday. WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and
Chick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks.
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFAGerman and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA)
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryCybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the
OpenAI says its AI models hacked Hugging Face during testingOpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment.
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsA single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkOpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models were operating with "reduced cyber refusals for evaluation purposes" that might otherwise limit their ability to
Police dismantle Kratos phishing platform, arrest developerAuthorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareA large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
Critical SharePoint RCE flaw exploited to steal machine keysHackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
- 1
- 2
- 3
- 4
- 5
- 6
- 1952