threat-intel Chick-fil-A Accounts Get Fried in Credential Stuffing Attack Chick-fil-A experienced a data breach due to credential stuffing attacks targeting its loyalty program accounts. Cybercriminals leveraged stolen credentials from various sources to gain unauthorized access, leading to th… SecurityWeek · Jul 23, 2026 Medium credential stuffingdata breachloyalty program
data-breach Major Australian energy supplier confirms customer data compromised Origin Energy, a major Australian energy provider, has confirmed a data breach impacting nearly 5 million customers. The breach exposed sensitive data including account details, credit card information, and personal iden… The Record · Jul 23, 2026 Medium AUdata breachcybersecurityaustralia
threat-intel One ChatGPT link could smuggle a rogue AI agent into your company This article is a collection of security and technology news snippets from The Register. It highlights a vulnerability impacting Joomla extensions, a Russian phishing campaign mimicking Signal support, and a general over… The Register · Jul 23, 2026 Medium IRvulnerabilityphishingransomware
threat-intel Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models SentinelOne has developed a new benchmark to assess how well frontier AI models can conduct thorough investigations of complex malware, using Fast16 – a malware linked to Iran’s nuclear program – as the test case. The be… SecurityWeek · Jul 23, 2026 Medium IRaimalwareinvestigation
vulnerability MZ Automation lib60870 A vulnerability in MZ Automation lib60870, version 2.4.0 and earlier, allows for a denial-of-service attack through an out-of-bounds read. This affects critical infrastructure sectors like chemical, energy, and water/was… CISA Advisories · Jul 23, 2026 Medium CVE-2026-16002GEout-of-boundsdenial of servicecisa
threat-intel Swiss train maker tells ransomware crooks to get off at the next stop This article is a collection of security-related news snippets from The Register. It covers a range of topics including a Swiss train maker’s response to ransomware attacks, a security acquisition, ransomware trends, vul… The Register · Jul 23, 2026 Medium ISIRransomwarevulnerabilityjoomla
threat-intel End-to-End Encryption and “Going Dark” This analysis examines the ongoing debate surrounding end-to-end encryption (E2EE) and government efforts to restrict its use. The paper argues that the assumption that E2EE completely prevents law enforcement access is… Schneier on Security · Jul 23, 2026 Medium encryptiongoing darksurveillance
data-breach Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses Upbound Group, a consumer finance company operating brands like Rent-A-Center, suffered a data breach resulting in approximately $13 million in fraudulent lease-to-own agreements. The company is investigating the inciden… SecurityWeek · Jul 23, 2026 Medium data breachfinancial servicescybersecurity
threat-intel Preview: Cisco Talos at Black Hat USA 2026 Cisco Talos will be at Black Hat USA 2026, showcasing research and demonstrations focused on AI-driven security challenges and threat hunting. They'll cover topics like AI-powered threat actor prompting, securing enterpr… Cisco Talos · Jul 23, 2026 Medium aithreat-huntingsecurity-operations
threat-intel Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts Google has introduced a new selfie video verification method to help users regain access to their accounts if they are locked out or unable to use traditional recovery options like email or phone number. This feature is… The Hacker News · Jul 23, 2026 Medium livenessfacial-recognitionauthentication
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
vulnerability Vulnérabilité dans Moodle (23 juillet 2026) A vulnerability in Moodle versions prior to 5.2.1 allows an attacker to compromise user data confidentiality. The CERT-FR has issued a security bulletin detailing the issue and recommending immediate patching. CERT-FR · Jul 23, 2026 Medium moodlevulnerabilitydata breach
vulnerability Multiples vulnérabilités dans Oracle Virtualization (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Virtualization, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. These vulnerabilities affect Oracle VM Virtu… CERT-FR · Jul 23, 2026 Medium CVE-2026-47041CVE-2026-47043CVE-2026-47044oraclevirtualizationvulnerabilities
threat-intel OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning OpenAI is facing scrutiny after a Chinese AI model developer, Hugging Face, reported an attack where malicious code was injected into their systems. This incident highlights the growing competition between Western and Ch… The Register · Jul 22, 2026 Medium CHUSaiopen-sourcesecurity
threat-intel Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill The House of Representatives passed a bill extending the 2015 Cybersecurity and Information Sharing Act (CISA 2015) for another decade as part of a larger defense bill. This extension provides legal protections for the p… The Record · Jul 22, 2026 Medium cisacybersecurityinformation sharing
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
threat-intel Linux kernel team publishes 432 CVEs in two days The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exp… The Register · Jul 22, 2026 Medium linuxkernelvulnerability
threat-intel StrongestLayer Raises $4.1 Million in Seed Funding Extension StrongestLayer, a cybersecurity startup, secured $4.1 million in seed funding to bolster its AI-powered email security platform. The company claims its system can detect a significant portion of modern email attacks that… SecurityWeek · Jul 22, 2026 Medium email securityaithreat detection
threat-intel Vibe-Coded Apps Riddled With Exploitable Security Flaws A recent study by Xint.io, a web platform specializing in AI-driven penetration testing, analyzed the security vulnerabilities introduced by ‘vibe coding’ – the increasing use of AI to assist in code generation. The stud… SecurityWeek · Jul 22, 2026 Medium aivibe-codingsecurity