threat-intel Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on col… CISA Advisories · Jul 15, 2026 Info vulnerabilitycvdsecurity
threat-intel SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. Traditional SASE security models are failing due to the shift to modern internet protocols and the rise of AI-powered workflows. Employees are now routinely sharing sensitive data with AI tools, bypassing traditional ne… The Hacker News · Jul 15, 2026 High aillmsaas
vulnerability Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addres… SecurityWeek · Jul 15, 2026 High CVE-2026-6875CVE-2026-14902CVE-2026-14903vulnerabilitypatchremote code execution
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal
vulnerability Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Google and Mozilla have released security updates for Chrome and Firefox, addressing several critical vulnerabilities. These updates include patches for zero-day exploits and prevent potential attacks. While exploit code… SecurityWeek · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764vulnerabilityzero-daypatch
threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
vulnerability Multiples vulnérabilités dans Mozilla Firefox (15 juillet 2026) Mozilla has announced multiple security vulnerabilities in Firefox, allowing attackers to bypass security policies and potentially cause unspecified security problems. These vulnerabilities require immediate patching to… CERT-FR · Jul 15, 2026 Medium CVE-2026-14906CVE-2026-15718CVE-2026-15719firefoxvulnerabilitysecurity
vulnerability Vulnérabilité dans Xen XAPI (15 juillet 2026) A security vulnerability has been identified in Xen XAPI, allowing attackers to bypass security policies. This could lead to unauthorized access and potential system compromise. The vulnerability is being addressed throu… CERT-FR · Jul 15, 2026 Medium CVE-2026-42491xenxapivulnerability
threat-intel 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems Researchers at Pennsylvania State University and Idaho National Laboratory have identified significant security vulnerabilities within 6 GHz Wi-Fi Automated Frequency Coordination (AFC) systems. These flaws could allow a… Dark Reading · Jul 14, 2026 High 6ghzwi-fispoofing
vulnerability Microsoft Patches a Record 570 Security Flaws Microsoft released a record 570 security updates for its Windows operating systems and other software, nearly triple the number from last month's Patch Tuesday. The surge in updates is largely due to the increasing use o… Krebs on Security · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayzero-dayvulnerability
threat-intel Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads A security vulnerability exists in the Claude for Chrome extension, allowing malicious extensions to trigger unauthorized actions within the user's Gmail, Google Docs, and Calendar accounts. The vulnerability stems from… The Hacker News · Jul 14, 2026 High prompt-injectionextensionvulnerability
vulnerability Adobe Patches Critical ColdFusion Vulnerabilities Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuse… SecurityWeek · Jul 14, 2026 High CVE-2026-48318CVE-2026-48322CVE-2026-48284securitypatchvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
vulnerability Vulnerability in FIFA’s Network A critical vulnerability in FIFA’s network allowed attackers to potentially gain control of the company’s systems, raising serious concerns about the security of FIFA’s operations and the data it handles. This incident h… Schneier on Security · Jul 14, 2026 High securitynetworkvulnerability
threat-intel [Video] Where protection starts: Cisco Talos Intelligence Integrations Cisco Talos Intelligence Integrations is a new system designed to help security teams better understand and respond to increasingly complex cyberattacks. By continuously applying threat intelligence across Cisco’s securi… Cisco Talos · Jul 14, 2026 Medium threat-intelligencesecurityintegration
threat-intel Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads xAI's Grok Build coding CLI has been uploading entire Git repositories, including commit history and sensitive data like API keys and passwords, to a Google Cloud Storage bucket. The issue was discovered by cereblab, who… The Hacker News · Jul 14, 2026 High data-breachgitcredentials
threat-intel New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Researchers have developed MemGhost, an automated tool that can plant false memories in AI assistants by sending a single, carefully crafted email. The tool bypasses existing security measures by exploiting the agents' a… The Hacker News · Jul 13, 2026 High CVE-2025-32711aimemory poisoningemail
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra