vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
vulnerability Default Azure Automation Setting Enables Cross-Tenant Identity Takeover A critical vulnerability in Microsoft's Azure Automation service, stemming from a default public configuration for automation account identities, could have allowed attackers to take over another tenant's identity and ac… Dark Reading · Jul 24, 2026 Critical CVE-2025-29827identitycloudautomation
threat-intel Uncle Sam tells overseas cybercrooks their visas are canceled This article covers a range of cybersecurity and technology news, including a US government action targeting Iranian propaganda sites, a security acquisition by EQT, and vulnerabilities impacting Joomla extensions. It al… The Register · Jul 24, 2026 Medium IRSWcybersecuritythreat intelligencevulnerability
threat-intel AegisAI Raises $36 Million for AI-Powered Email Security AegisAI, a startup specializing in AI-powered email security, has raised $36 million in Series A funding to bolster its autonomous detection agents and expand its market reach. The company’s platform utilizes AI to analy… SecurityWeek · Jul 24, 2026 Medium aiphishingemail_security
vulnerability Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Bing Image Search had two critical vulnerabilities allowing attackers to execute commands as SYSTEM on Microsoft's servers by submitting crafted SVGs. The issue stemmed from a helper component that treated SVG files as c… The Hacker News · Jul 24, 2026 High CVE-2026-32194CVE-2026-32191CVE-2016-3714svgcommand-injectionimagemagick
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
vulnerability Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, impacting versions prior to 150.0.4078.96. The exact nature of the vulnerabilities and the resulting security issue are not specified by the publisher. Use… CERT-FR · Jul 24, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415vulnerabilitypatchsecurity
threat-intel International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers, operating under the APT group Laundry Bear, are targeting governmental and commercial organizations globally through zero-click phishing campaigns exploiting a vulnerability in Zimbra webma… The Record · Jul 23, 2026 High CVE-2025-66376UKRUNEzero-clickphishingzimbra
threat-intel Oracle drops 1,449 security patches like it's the new normal This article is a collection of security-related news snippets from The Register. It covers a range of topics including security patches from Oracle, advancements in AI hardware (AMD vs Nvidia), phishing attacks targetin… The Register · Jul 23, 2026 Medium CVE-2026-47056CVE-2026-60217CVE-2026-61211securityvulnerabilitiesphishing
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel One ChatGPT link could smuggle a rogue AI agent into your company This article is a collection of security and technology news snippets from The Register. It highlights a vulnerability impacting Joomla extensions, a Russian phishing campaign mimicking Signal support, and a general over… The Register · Jul 23, 2026 Medium IRvulnerabilityphishingransomware
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
threat-intel OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning OpenAI is facing scrutiny after a Chinese AI model developer, Hugging Face, reported an attack where malicious code was injected into their systems. This incident highlights the growing competition between Western and Ch… The Register · Jul 22, 2026 Medium CHUSaiopen-sourcesecurity
threat-intel Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing… Graham Cluley · Jul 22, 2026 High NEUKNAcyberattackintelrussian
threat-intel Linux kernel team publishes 432 CVEs in two days The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exp… The Register · Jul 22, 2026 Medium linuxkernelvulnerability
threat-intel Greedy ransomware crews return for seconds after victims cough up first extortion payments This article covers a variety of cybersecurity and technology news items, including a ransomware resurgence targeting victims after initial payments, a new AMD AI compute platform competing with Nvidia, a security vulner… The Register · Jul 22, 2026 Medium ransomwarevulnerabilitycybersecurity
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution