threat-intel LAPD sidelines relationship with license-plate reader company Flock Safety The Los Angeles Police Department (LAPD) is pausing its relationship with Flock Safety, an ALPR camera company, due to concerns about data privacy, security, and control. The decision follows an inspector general’s audit… The Record · Jul 15, 2026 Medium alprsurveillanceprivacy
vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
threat-intel White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The White House has launched Gold Eagle, a new initiative designed to streamline vulnerability detection and remediation across government and industry. This program leverages AI, specifically Anthropic's Mythos, to proa… SecurityWeek · Jul 15, 2026 Medium vulnerabilityaicybersecurity
vulnerability Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands SonicWall has warned of active exploitation of two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. One vulnerability allows unauthenticated attackers to make requests to unintended loca… The Hacker News · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode injection
threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability
threat-intel Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft released its largest Patch Tuesday update to date, encompassing 622 security updates, with two of these fixes already being actively exploited by attackers. These vulnerabilities, affecting SharePoint Server an… The Hacker News · Jul 14, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-50661zero-dayprivilege escalationremote code execution
threat-intel 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems Researchers at Pennsylvania State University and Idaho National Laboratory have identified significant security vulnerabilities within 6 GHz Wi-Fi Automated Frequency Coordination (AFC) systems. These flaws could allow a… Dark Reading · Jul 14, 2026 High 6ghzwi-fispoofing
vulnerability Microsoft Patches a Record 570 Security Flaws Microsoft released a record 570 security updates for its Windows operating systems and other software, nearly triple the number from last month's Patch Tuesday. The surge in updates is largely due to the increasing use o… Krebs on Security · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayzero-dayvulnerability
threat-intel Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook? Several states – Illinois, New York, and California – are enacting laws to regulate the deployment of increasingly powerful frontier AI models, requiring developers to establish comprehensive AI frameworks addressing ris… Dark Reading · Jul 14, 2026 High aifrontier-airegulation
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
threat-intel US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Russian state-sponsored APT actors are actively targeting routers worldwide to compromise critical infrastructure. These attacks involve exploiting vulnerabilities and leveraging SNMP to steal device configurations and t… SecurityWeek · Jul 14, 2026 High CVE-2008-4128CVE-2018-0171USAUCAsnmpciscorouter
threat-intel Valarian Raises $50 Million for Sovereign Infrastructure Control Layer Valarian, a UK-based company focused on sovereign infrastructure control, has secured $50 million in Series A funding to bolster its platform, ACRA. ACRA is designed to provide a layer of control and governance for AI mo… SecurityWeek · Jul 14, 2026 Medium UKsovereigntydata-controlkubernetes
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel Weak Security Continues to Fuel Russian Cyberattacks The UK and EU have jointly sanctioned Russian individuals and entities involved in cyberattacks and disinformation campaigns, coinciding with a US cybersecurity advisory highlighting ongoing Russian state-sponsored attac… Dark Reading · Jul 13, 2026 High UKEUUNrouter securityciscosnmp
threat-intel Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach Russian journalist Ksenia Sobchak's Telegram channels were briefly taken over by hackers who published alleged private correspondence. The hackers, operating under the group Black Mirror, claimed to have stolen over 350G… The Record · Jul 13, 2026 Medium RUUKtelegramdata breachrussian
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
threat-intel EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign The European Union has imposed sanctions on Russian intelligence officers and entities involved in a long-running cyber espionage campaign targeting European governments and critical infrastructure. This campaign, spanni… SecurityWeek · Jul 13, 2026 High FRDEPLcyber espionagecritical infrastructurerussian threat