threat-intel SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch SonicWall appliances were targeted by threat actors exploiting two unpatched zero-days for weeks before a fix was released. The attackers, tracked as UTA0533, deployed custom malware – KnuckleBall, OrangeTail, and Suo5 –… SecurityWeek · Jul 20, 2026 High CVE-2026-15409CVE-2026-15410zero-dayexploitmalware
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
vulnerability Multiples vulnérabilités dans Cisco RoomOS (16 juillet 2026) Multiple vulnerabilities have been discovered in Cisco RoomOS, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the operating… CERT-FR · Jul 16, 2026 Medium CVE-2026-20150CVE-2026-20153CVE-2026-20156ciscoroomosvulnerability
threat-intel SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them… SecurityWeek · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode_injection
threat-intel Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal Cribl, a telemetry processing platform, has acquired CardinalOps to bolster its security operations capabilities. This acquisition will allow Cribl customers to map their existing detection rules and security controls to… Dark Reading · Jul 15, 2026 Medium mitre attckdetection engineeringsecurity operations
threat-intel How Pentera Turns AI Security Workflows into Validation Engines Pentera has introduced a new protocol, MCP, to integrate its security validation platform directly into existing AI security workflows. Traditionally, AI security tools relied on fragmented risk signals, leading to guess… The Hacker News · Jul 14, 2026 High aivalidationattack-path
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel WhatsApp says NSO targeted users with spearfishing attacks in violation of court order WhatsApp has accused NSO Group of violating a court order by conducting spearfishing attacks against its users, utilizing social engineering techniques to lure individuals into clicking malicious links. This follows a pr… The Record · Jun 8, 2026 High USspear-phishingsocial-engineeringspyware
other Hands on with Intelligent Terminal, an AI-powered Windows Terminal Microsoft has released Intelligent Terminal, an open-source extension for Windows Terminal that integrates AI assistance directly into the terminal environment. The tool leverages various AI models, such as GitHub Copilo… BleepingComputer · Jun 7, 2026 Low aiwindowsterminal
threat-intel Zoom CISO: AI as Security Enabler, Not Role-Replacer This article features an interview with Sandra McLeod, CISO at Zoom, discussing the evolving role of AI in cybersecurity. McLeod emphasizes that AI should be viewed as an enabler for security teams, automating repetitive… Dark Reading · Jun 2, 2026 Medium aisecurityautomation
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago