threat-intel Synopsys Finds No Evidence of Data Breach Following Bosch Hack Claims A cybercrime group claiming to have hacked Synopsys and Bosch is demanding a ransom for stolen data, but Synopsys denies the claims and has found no evidence of a data breach. Bosch declined to comment, offering a standa… SecurityWeek · Jul 14, 2026 Medium DEcybercrimeextortiondata breach
vulnerability Adobe Patches Critical ColdFusion Vulnerabilities Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuse… SecurityWeek · Jul 14, 2026 High CVE-2026-48318CVE-2026-48322CVE-2026-48284securitypatchvulnerability
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
threat-intel US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Russian state-sponsored APT actors are actively targeting routers worldwide to compromise critical infrastructure. These attacks involve exploiting vulnerabilities and leveraging SNMP to steal device configurations and t… SecurityWeek · Jul 14, 2026 High CVE-2008-4128CVE-2018-0171USAUCAsnmpciscorouter
threat-intel Valarian Raises $50 Million for Sovereign Infrastructure Control Layer Valarian, a UK-based company focused on sovereign infrastructure control, has secured $50 million in Series A funding to bolster its platform, ACRA. ACRA is designed to provide a layer of control and governance for AI mo… SecurityWeek · Jul 14, 2026 Medium UKsovereigntydata-controlkubernetes
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
policy Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules The Pentagon is delaying the second phase of the Cybersecurity Maturity Model Certification (CMMC) program, intended to streamline contractor cybersecurity rules and address a shortage of qualified third-party assessors.… SecurityWeek · Jul 14, 2026 Info cmmccybersecuritycontractor
threat-intel Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Jesse McGraw, once a notorious blackhat hacker known as GhostExodus and leader of the Electronik Tribulation Army (ETA), has undergone a dramatic transformation. Driven by a complex mix of factors including neurodiversit… SecurityWeek · Jul 13, 2026 High neurodiversityred-hatosint
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra
threat-intel EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign The European Union has imposed sanctions on Russian intelligence officers and entities involved in a long-running cyber espionage campaign targeting European governments and critical infrastructure. This campaign, spanni… SecurityWeek · Jul 13, 2026 High FRDEPLcyber espionagecritical infrastructurerussian threat
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
data-breach Centers Laboratory Data Breach Affects 540,000 Individuals Centers Laboratory, a healthcare diagnostics company, suffered a data breach in August 2025, exposing the personal and protected health information of over 540,000 individuals. The breach was carried out by the WorldLeak… SecurityWeek · Jul 13, 2026 High data breachcybercrimehealthcare
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
threat-intel Third US Security Expert Sentenced to Prison for Helping Ransomware Gang A former cybersecurity expert, Angelo Martino, was sentenced to 70 months in prison for aiding a ransomware gang, BlackCat/Alphv, by providing confidential information to maximize ransom payments. Two other cybersecurity… SecurityWeek · Jul 10, 2026 Critical ransomwareinsider threatcybercrime