threat-intel Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026) Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service. These vulnerabilities are… CERT-FR · Jul 22, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-16349vulnerabilityfirefoxsecurity
vulnerability Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking products, allowing an attacker to execute arbitrary code, compromise data confidentiality, and bypass security policies. These vulnerabilities affect… CERT-FR · Jul 22, 2026 High CVE-2026-35387CVE-2026-44878CVE-2026-44879vulnerabilitypatchsecurity
threat-intel Cisco's open-weight bug busters take on Google and OpenAI This article covers a variety of cybersecurity and technology news items, including Cisco's efforts to compete with Nvidia's AI hardware, a security breach involving Joomla extensions, and various other developments in t… The Register · Jul 21, 2026 Medium securitycybersecurityjoomla
threat-intel Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has finally fixed a significant security flaw in its Hide My Email service, which allowed real email addresses to be exposed in mail logs. The issue stemmed from sending a rejected spam email to a Hide My Email use… The Hacker News · Jul 21, 2026 Medium privacysecurityicloud
data-breach AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert An AI music platform, Suno, experienced a data breach exposing 55 million user accounts. Security expert claims the breach highlights vulnerabilities in the platform's security practices. The incident underscores the gro… The Register · Jul 21, 2026 Medium data breachaisecurity
threat-intel Captive Portal Detection, (Tue, Jul 21st) This article details how operating systems and browsers detect captive portals – the splash screens that appear when connecting to public Wi-Fi networks. Instead of intercepting old non-TLS homepages, these systems now… SANS Internet Storm Center · Jul 21, 2026 Medium captive portalwifinetwork detection
vulnerability Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra has released patches to address nine security vulnerabilities, including a critical SNMP command injection flaw and several XSS vulnerabilities. These fixes are vital to mitigate potential code execution and email… The Hacker News · Jul 21, 2026 Medium CVE-2026-50055snmpxsscommand-injection
threat-intel Choose Wisely: AI-Generated Coding Risk Varies, A Lot A Secure Code Warrior study revealed that AI-generated code introduces a significant number of vulnerabilities – an average of 15 per codebase – but the risk varies greatly depending on the development framework used. Th… Dark Reading · Jul 21, 2026 Medium aicodevulnerability
vulnerability Zimbra Update Patches Critical Vulnerabilities Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essent… SecurityWeek · Jul 21, 2026 Critical CVE-2026-50055CVE-2026-10631CVE-2026-50054command injectionxssssrf
vulnerability Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released p… The Hacker News · Jul 21, 2026 Critical CVE-2026-6875vulnerabilitycode executionsandbox
threat-intel Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push Ivanti is leveraging large language models (LLMs) to automate vulnerability remediation and discovery, a project initially sparked by the surprising effectiveness of the Claude 4.6 model. Daniel Spicer, Ivanti’s CSO, des… Dark Reading · Jul 20, 2026 Medium CVE-2026-10520llmvulnerabilityautomation
threat-intel 25 Years After Code Red: What the Worm Era Can Teach Us About AI Security Twenty-five years after the Code Red worm, a pivotal moment in cybersecurity history, experts are drawing parallels to the current rush towards AI adoption. The article highlights how Code Red exploited a widespread, oft… Dark Reading · Jul 20, 2026 Medium CHaisecurityvulnerability
threat-intel Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software Neo, a cybersecurity startup led by former SentinelOne executives, has raised $100 million to provide enterprises with a control layer for AI software, addressing the growing concern of AI agents embedded in various appl… SecurityWeek · Jul 20, 2026 Medium aiagenticcybersecurity
vulnerability Chrome 150 Update Patches Severe Memory Safety Bugs Google released Chrome 150 to address seven memory safety vulnerabilities, including critical use-after-free flaws within components like CameraCapture and GPU. While no exploits have been reported, Google urges users to… SecurityWeek · Jul 20, 2026 High memory-safetyvulnerabilitychrome
threat-intel World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent Hugging Face, a leading AI model repository, was hacked by an autonomous AI agent system. The attacker gained access to internal datasets and credentials, moving laterally across several clusters. While public-facing mod… The Hacker News · Jul 20, 2026 High CHaiautonomous agentsecurity
supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
threat-intel Friday Squid Blogging: Squid Washing Up on Cape Cod Beach This article is a commentary piece from Schneier on Security, referencing a beach discovery of squid and using it as a springboard to discuss security news stories he hasn't yet addressed. It’s a meta-commentary on the s… Schneier on Security · Jul 17, 2026 Info securitycommentarymeta
threat-intel The Real AI Threat Is Blind Trust A recent attack exploited a vulnerability in AI systems, allowing attackers to manipulate one AI agent into generating instructions for another, leading to unauthorized fund transfers. This highlights a growing risk as A… Dark Reading · Jul 17, 2026 High NOaiautomationgovernance