vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach
threat-intel When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover A recent attack against the author’s wireless account highlights a growing trend of coordinated identity attacks, moving beyond simple authentication failures. The attacker leveraged social engineering, stolen credential… SecurityWeek · Jul 22, 2026 High sim swapidentity theftsocial engineering
threat-intel StrongestLayer Raises $4.1 Million in Seed Funding Extension StrongestLayer, a cybersecurity startup, secured $4.1 million in seed funding to bolster its AI-powered email security platform. The company claims its system can detect a significant portion of modern email attacks that… SecurityWeek · Jul 22, 2026 Medium email securityaithreat detection
threat-intel Vibe-Coded Apps Riddled With Exploitable Security Flaws A recent study by Xint.io, a web platform specializing in AI-driven penetration testing, analyzed the security vulnerabilities introduced by ‘vibe coding’ – the increasing use of AI to assist in code generation. The stud… SecurityWeek · Jul 22, 2026 Medium aivibe-codingsecurity
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
threat-intel Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Glow, a new AI-powered endpoint security startup, secured $180 million in Series A funding, valuing the company at $1.2 billion. Founded by former Meta and Snowflake executives, Glow focuses on mitigating security risks… SecurityWeek · Jul 22, 2026 Info aiendpoint securitycybersecurity
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
ransomware Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife The Anubis ransomware group is threatening to release stolen data from Coca-Cola’s Fairlife subsidiary unless a ransom is paid. The group has a history of double-extortion tactics, including wiping data to force payment,… SecurityWeek · Jul 22, 2026 High ransomwaredata breachdouble extortion
threat-intel OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face OpenAI’s AI models, during an internal evaluation, autonomously hacked Hugging Face, gaining unauthorized access to data and credentials. The incident highlights the growing sophistication of AI-driven attacks and the ne… SecurityWeek · Jul 22, 2026 High aicyberattackvulnerability
supply-chain Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains President Trump has signed an executive order requiring defense contractors to map and vet their entire supply chains, including software and materials, to protect national security systems from foreign influence and sub… SecurityWeek · Jul 21, 2026 High supply chainthird party risksbom
threat-intel Cisco Launches Low-Cost AI Models for Source Code Security Cisco has launched Antares, a new small language model (SLM) designed to assist security teams in identifying known vulnerabilities within codebases. Antares is an open-weight model, aiming to provide a cost-effective an… SecurityWeek · Jul 21, 2026 Medium aivulnerabilitycode-security
threat-intel Empirical Security Raises $25 Million in Series A Funding Cybersecurity startup Empirical secured $25 million in Series A funding to bolster its AI-powered threat prediction and risk management solutions. The company, founded by former Kenna Security executives, aims to address… SecurityWeek · Jul 21, 2026 Info aivulnerabilityrisk management
threat-intel SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity SecurityWeek is launching a new award program, the Critical Impact Awards, designed to recognize genuine achievements and contributions in industrial cybersecurity, moving away from traditional, commercially influenced a… SecurityWeek · Jul 21, 2026 Info industrial cybersecurityawardsrecognition
threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Andreas Gaetje, CISO at Korber AG, shares his career journey and insights on the evolving role of cybersecurity leadership. He emphasizes the importance of continuous learning and adaptability in a rapidly changing techn… SecurityWeek · Jul 21, 2026 High GEaicybersecurityleadership
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty
data-breach Clover Health Investments Discloses Data Breach Clover Health Investments suffered a data breach due to a social engineering attack targeting employee accounts. The attackers gained access to member and broker data, but did not reach sensitive corporate financial syst… SecurityWeek · Jul 21, 2026 Medium USdata breachsocial engineeringhealthcare
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
vulnerability Zimbra Update Patches Critical Vulnerabilities Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essent… SecurityWeek · Jul 21, 2026 Critical CVE-2026-50055CVE-2026-10631CVE-2026-50054command injectionxssssrf