threat-intel Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline A coordinated cyberattack targeted over 30 community water systems in Minnesota, leading to operational disruptions and communications failures. While the exact number of compromised systems remains unclear, the attacks… The Hacker News · Jul 29, 2026 High UNcritical infrastructureindustrial control systemscyberattack
threat-intel CI Fortify – Advice for isolating vital systems The U.S. government, through CISA and ASD’s ACSC, has released guidance for critical infrastructure organizations to isolate vital operational technology and enabling systems from other networks. This proactive measure i… CISA Advisories · Jul 28, 2026 Medium critical infrastructurecybersecurityisolation
threat-intel Act Security Emerges from Stealth to Fight the Patch Problem Act Security, a Tel-Aviv-based cybersecurity firm founded by the team behind Medigate, has emerged from stealth with $60 million in funding to address the growing problem of excessive cloud access sprawl and the difficul… SecurityWeek · Jul 28, 2026 Medium IScloud securityaccess controlvulnerability management
vulnerability Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Arista Networks has patched a vulnerability in its VeloCloud software that was being actively exploited. The CISA (Cybersecurity and Infrastructure Security Agency) issued an advisory urging administrators to address the… The Register · Jul 28, 2026 High CVE-2026-16812patchvulnerabilitynetwork
vulnerability Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Arista Networks has released patches for a critical zero-day vulnerability in its VeloCloud Orchestrator, which has been actively exploited in the wild. The flaw allows remote access to privileged functionality, and no s… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2022-42475zero-daypatchvulnerability
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
vulnerability Rockwell Patches Code Execution Flaws in Arena Simulation Software Rockwell Automation has released a patch to address four critical vulnerabilities in its Arena Simulation software, preventing attackers from executing arbitrary code on affected systems. These flaws stem from improper d… SecurityWeek · Jul 25, 2026 Critical CVE-2026-8085CVE-2026-8312CVE-2026-8313otsimulationmemory corruption
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
threat-intel Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets Russian state-sponsored threat actors, dubbed ‘Laundry Bear,’ have been exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to target Western governments and enterprises, including US and U… Dark Reading · Jul 23, 2026 High CVE-2025-66376NLUSUAzimbraxssphishing
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
threat-intel Assaf Keren Appointed New CISO of Meta Assaf Keren is taking over as Meta's CISO, replacing Guy Rosen after 13 years at the company. He brings a wealth of experience from PayPal and Qualtrics, focusing on building trust and security at scale for Meta’s massiv… SecurityWeek · Jul 23, 2026 Info cisocybersecurityleadership
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Mythos Didn't Break Your Security Program. Your Exposure Window Could. The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actua… The Hacker News · Jul 20, 2026 High vulnerabilitiesexposure windowattack path analysis
threat-intel Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle, a voluntary initiative aimed at coordinating vulnerability response across critical infrastructure sectors, leveraging AI to accelerate the patching process. However, the initiative i… Dark Reading · Jul 17, 2026 Medium vulnerabilityaicybersecurity
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
threat-intel Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities The Trump administration has launched Gold Eagle, a new AI-powered cybersecurity clearinghouse to rapidly identify, prioritize, and patch vulnerabilities across industry and critical infrastructure. This initiative, driv… The Record · Jul 15, 2026 Medium vulnerabilitiesaicybersecurity
threat-intel Guten Tag, Bonjour, Hola to Our European Cyber Defenders! Dark Reading is launching a new section, DR Global Europe, to provide region-specific cybersecurity intelligence tailored for professionals in the EU and UK. This expansion addresses unique cyber threats facing Europe, i… Dark Reading · Jul 15, 2026 High RUUKSPcybersecurityddosransomware