all—News
Top News
CISA warns admins to patch actively exploited SharePoint flaws
July 15, 2026CISA orders feds to patch actively exploited Oracle flaw by Saturday
July 16, 2026Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
July 14, 2026Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
July 15, 2026Microsoft releases Windows 10 KB5099539 extended security update
July 14, 2026Microsoft: Some Dell PCs shut down after recent Windows updates
July 15, 2026Latest News
Estée Lauder discloses data breach via Oracle E-Business flawCosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
SonicWall SMA1000 flaws exploited as zero-days to push custom malwareTwo recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Hackers steal $23.7 million in crypto from Ostium in off-chain attackThe Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapesResearchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings.
JadePuffer agentic attacks now target AI model data with ransomwareThe JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareCybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
New HollowGraph malware uses Microsoft Graph for stealthy C2 commsA malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignA malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
- // no coverServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unearthed by Searchlight Cyber researchers and reported to ServiceNow in early April 2026. The
- 1
- 2
- 3
- 4
- 5
- 6
- 1945