threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer active since 2024, is leveraging deceptive lures – primarily mimicking Claude AI assistant pages and fake CAPTCHAs – to steal browser credentials, Microsoft 365 files, and sensitive documents.… The Hacker News · Jul 17, 2026 High infostealerdeceptive lureransomware
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
vulnerability Multiples vulnérabilités dans Microsoft Windows (17 juillet 2026) Microsoft has announced multiple vulnerabilities across various versions of Windows, including Windows 10 and 11. These vulnerabilities could allow attackers to execute arbitrary code remotely, elevate privileges, and co… CERT-FR · Jul 17, 2026 High CVE-2026-56171CVE-2026-58598CVE-2026-58643windowsvulnerabilitypatch
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft products, primarily within SharePoint, allowing attackers to compromise data confidentiality and bypass security policies. Microsoft has released security bullet… CERT-FR · Jul 17, 2026 Medium CVE-2026-56171CVE-2026-62826sharepointvulnerabilitymicrosoft
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel Sandworm hackers have a CAPTCHA trick for Ukrainians Sandworm, a hacking group linked to Russia's military intelligence, is using a sophisticated CAPTCHA trick to trick Ukrainian targets into installing malware on their computers. The group employs a 'ClickFix' technique,… The Record · Jul 16, 2026 High RUsocial engineeringmalware distributionransomware
threat-intel Two Scattered Spider Hackers Sentenced to Jail in UK Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to prison in the UK for their role in a 2024 attack on Transport for London, resulting in significant financial losses.… SecurityWeek · Jul 16, 2026 High UKUSEScybercrimeukscattered spider
threat-intel Old UEFI Shims Expose Systems to Secure Boot Bypass A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating ba… SecurityWeek · Jul 16, 2026 High CVE-2026-8863CVE-2026-10797uefisecure bootvulnerability
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
threat-intel Forgotten Bootloaders Expose Secure Boot Blind Spot Researchers discovered 11 vulnerable, but still trusted, UEFI shim bootloaders that could have been used to bypass Secure Boot on systems relying on Microsoft's third-party UEFI signing certificate. Despite being outdate… Dark Reading · Jul 15, 2026 High secure bootfirmwareuefi
threat-intel Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife The UK is intensifying its push for tech sovereignty, driven by concerns over reliance on US tech companies, particularly in the rapidly developing field of AI. Recent restrictions on AI models from Anthropic and OpenAI… Dark Reading · Jul 15, 2026 High UKUSCHtech-sovereigntyaicybersecurity
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
threat-intel Windows Bind Link Attacks Can Hide Malware From EDR Tools Researchers at Bitdefender have demonstrated three techniques leveraging Windows’ bind links to evade Endpoint Detection and Response (EDR) tools. These techniques – file-binding, process-binding, and silo-binding – allo… SecurityWeek · Jul 15, 2026 High bind linksedr evasionwindows security
vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability