threat-intel Council worker spared prison after four-day data-snooping spree This article is a collection of security and technology news snippets. A House worker was spared prison after a data snooping spree, while Microsoft’s SharePoint remains vulnerable to zero-day attacks. Additionally, a Ru… The Register · Jul 22, 2026 Medium RUSWphishingvulnerabilitycybersecurity
threat-intel Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement dismantled Kratos, a widely used criminal phishing kit, after arresting the developer and taking down over 200 servers. The kit, used by approximately 1,800 customers, was designed to steal… The Hacker News · Jul 22, 2026 High DEUSIDphishingcredential theftmfa bypass
threat-intel Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A vulnerability in Microsoft Azure DevOps's MCP server allows attackers to hijack AI coding agents by inserting hidden HTML comments in pull requests. These comments can then instruct the agent to perform actions – like… The Hacker News · Jul 22, 2026 High prompt-injectionai-riskmicrosoft
threat-intel OpenAI admits it was the source of the agent swarm that attacked Hugging Face OpenAI is facing accusations of orchestrating an attack against Hugging Face, a major AI platform. The incident involved a coordinated effort by AMD and Cerebras to undermine Nvidia's dominance in AI compute, with OpenAI… The Register · Jul 22, 2026 Medium CHIRaicyberattackvulnerability
threat-intel Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task Large language models (LLMs) are not effectively addressing vulnerability prioritization for application security teams, with a significant number of flagged vulnerabilities proving to be false positives or irrelevant du… Dark Reading · Jul 21, 2026 Medium aivulnerabilityappsec
threat-intel AI's cheatin' heart will make you weep This article covers a range of cybersecurity and technology news, including AMD's challenge to Nvidia in AI compute, security vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, an… The Register · Jul 21, 2026 Medium USIRSWcybersecurityphishingransomware
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
threat-intel Captive Portal Detection, (Tue, Jul 21st) This article details how operating systems and browsers detect captive portals – the splash screens that appear when connecting to public Wi-Fi networks. Instead of intercepting old non-TLS homepages, these systems now… SANS Internet Storm Center · Jul 21, 2026 Medium captive portalwifinetwork detection
threat-intel Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX have discovered a significant vulnerability in five popular open-source Android mobile agent frameworks. These age… The Hacker News · Jul 21, 2026 High CVE-2026-25592CVE-2026-26030CHHOmobile-securityprompt-injectionusb-debugging
threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel N-day is Becoming N-Hour. Patching Faster Won't Save You. The speed at which attackers can now weaponize security patches has dramatically decreased, shrinking the window between a patch's release and a successful exploit. Traditionally, defenders had weeks to react, but now, t… The Hacker News · Jul 21, 2026 High vulnerabilityexploitai
threat-intel New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Researchers at Zhejiang University have discovered a method to potentially disrupt power grids using cloud GPUs. Dubbed ‘Bit2Watt,’ the technique involves manipulating a GPU’s power draw – switching between high-intensit… The Hacker News · Jul 21, 2026 High CHgpupower gridcybersecurity
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
threat-intel Attackers pummel critical WordPress vuln to create all sorts of mischief This article covers a range of cybersecurity and technology news, including a vulnerability exploited to create mischief, a Russian phishing campaign mimicking Signal support, and a significant acquisition in the cyberse… The Register · Jul 20, 2026 Medium CVE-2026-63030CVE-2026-60137vulnerabilityphishingransomware
threat-intel Scammers impersonate FBI on social media, prey on crime victims Scammers are impersonating the FBI on social media to trick victims, particularly those involved in crime, into divulging sensitive information. This tactic is part of a broader trend of online fraud and disinformation c… The Register · Jul 20, 2026 Medium CHsocial engineeringphishingfraud
threat-intel Malicious cloud customers can bring down the power grid This article covers a range of cybersecurity and technology news, including a report on Russian phishing attacks posing as Signal support, a Microsoft SharePoint vulnerability, and a broader discussion about the evolving… The Register · Jul 20, 2026 Medium IRphishingvulnerabilityransomware
threat-intel HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A sophisticated espionage implant, dubbed HollowGraph, is using a hijacked Microsoft 365 calendar as its command and control channel to steal data and deliver instructions. The malware, linked to the Iranian threat group… The Hacker News · Jul 20, 2026 High ISIRespionagecommand-and-controlmicrosoft 365
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft