vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability 2-Click Cursor Exploit Enables Dev Environment Takeover A vulnerability in Cursor AI, an AI coding tool used by over 50,000 enterprises including 64% of the Fortune 500, allows attackers to install malicious code through a cleverly disguised pull request link. Researchers at… Dark Reading · Jul 15, 2026 High aisecuritypull request
threat-intel US Charges Russian Individuals and Firms for Running Cybercrime Services The US Justice Department has charged three Russian nationals and two companies – ML.Cloud and Media Land – with operating cybercrime services that facilitated attacks against numerous US entities, resulting in tens of m… SecurityWeek · Jul 15, 2026 High CNNLFIcybercrimehostingservicesrussian
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
threat-intel Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits Nigeria is experiencing a significant rise in cybercrime losses despite a decrease in reported incidents, driven by increasingly sophisticated schemes and a growing digital economy. The country is actively developing cyb… Dark Reading · Jul 15, 2026 High NGcybercrimecybersecurityfraud
vulnerability Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th) Microsoft's July Patch Tuesday release includes a massive 622 vulnerabilities, with a significant number already exploited. Many of these vulnerabilities affect products like Edge and SharePoint, and a notable one – a B… SANS Internet Storm Center · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayvulnerabilitymicrosoft
threat-intel Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads A security vulnerability exists in the Claude for Chrome extension, allowing malicious extensions to trigger unauthorized actions within the user's Gmail, Google Docs, and Calendar accounts. The vulnerability stems from… The Hacker News · Jul 14, 2026 High prompt-injectionextensionvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
policy EU leaders eye social media ban for children under age 13 European leaders, led by Ursula von der Leyen, are pushing for a EU-wide ban on social media for children under 13, arguing that it's a necessary step to protect children's mental health and safety. Current age restricti… The Record · Jul 13, 2026 Info social mediachildrenregulation
threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
threat-intel Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling Meta has filed a patent for an AI system that continuously monitors a user's voice, eye movements, and device usage to analyze their emotional state and provide personalized feedback. The system would track speech patter… The Hacker News · Jul 13, 2026 High aiprivacyemotion-analysis
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
threat-intel More Countries Jump on the Social Media Ban Wagon More countries are implementing social media bans for minors, driven by concerns about mental health and safety. However, companies are struggling to comply while minimizing user disruption and avoiding intrusive data co… Dark Reading · Jul 10, 2026 Medium AUUNsocial mediaage verificationprivacy
threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
threat-intel Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor gro… SecurityWeek · Jul 10, 2026 High vishingpasskeyphishing
threat-intel AI Surveillance and Social Progress This article explores the growing threat of AI-powered surveillance systems, particularly in China, and their potential to significantly erode personal freedoms and democratic progress. The author argues that these syste… Schneier on Security · Jul 10, 2026 High CHUSGEsurveillanceaifacial recognition
threat-intel Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining un… The Hacker News · Jul 10, 2026 High passkeyphishingvishing