all—News
Top News
CISA warns admins to patch actively exploited SharePoint flaws
July 15, 2026CISA orders feds to patch actively exploited Oracle flaw by Saturday
July 16, 2026Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
July 14, 2026Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
July 15, 2026Microsoft releases Windows 10 KB5099539 extended security update
July 14, 2026Microsoft: Some Dell PCs shut down after recent Windows updates
July 15, 2026Latest News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessThreat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
Zimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesZimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsAn Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
N-day is Becoming N-Hour. Patching Faster Won't Save You.Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock starts, and defenders try to deploy
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitA cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power
US seizes over 1,000 websites in FIFA World Cup piracy crackdownThe U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization.
Critical Palo Alto VPN bug now exploited by Qilin ransomware gangThe Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
Microsoft shares manual fix for WSUS sync delays and timeoutsMicrosoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
Estée Lauder discloses data breach tied to Oracle EBS vulnerabilityCosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, fragrance, and haircare brands. “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the
- 1
- 2
- 3
- 4
- 5
- 6
- 1949