threat-intel Act Security Emerges from Stealth to Fight the Patch Problem Act Security, a Tel-Aviv-based cybersecurity firm founded by the team behind Medigate, has emerged from stealth with $60 million in funding to address the growing problem of excessive cloud access sprawl and the difficul… SecurityWeek · Jul 28, 2026 Medium IScloud securityaccess controlvulnerability management
data-breach Pope's official prayer app commits cardinal sin, leaks 700K+ users' info Pope's official prayer app, ‘Divine Office,’ has suffered a significant data breach, exposing the personal information of over 700,000 users. The vulnerability stemmed from a flawed patch, allowing attackers to exploit a… The Register · Jul 24, 2026 High data breachmobile securityvulnerability
threat-intel Is Patching Dead? Vulnerability Management in the Post-Mythos Era The U.S. government is deploying a new AI-powered system, Gold Eagle, to proactively identify and remediate software vulnerabilities across federal agencies and critical infrastructure. This initiative is driven by the i… SecurityWeek · Jul 23, 2026 High USvulnerabilityaicybersecurity
threat-intel Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026) Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service. These vulnerabilities are… CERT-FR · Jul 22, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-16349vulnerabilityfirefoxsecurity
threat-intel Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google has launched Gemini 3.5 Flash Cyber, a specialized AI model designed to rapidly identify and fix software vulnerabilities. This AI model, accessible only to governments and trusted partners through CodeMender, sig… The Hacker News · Jul 21, 2026 High aivulnerabilitycybersecurity
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
threat-intel Mythos Didn't Break Your Security Program. Your Exposure Window Could. The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actua… The Hacker News · Jul 20, 2026 High vulnerabilitiesexposure windowattack path analysis
threat-intel Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle, a voluntary initiative aimed at coordinating vulnerability response across critical infrastructure sectors, leveraging AI to accelerate the patching process. However, the initiative i… Dark Reading · Jul 17, 2026 Medium vulnerabilityaicybersecurity
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (17 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. These vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The affected products range from deskt… CERT-FR · Jul 17, 2026 High CVE-2023-53995CVE-2025-68324CVE-2025-71089vulnerabilitylinuxsecurity
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
threat-intel Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities The Trump administration has launched Gold Eagle, a new AI-powered cybersecurity clearinghouse to rapidly identify, prioritize, and patch vulnerabilities across industry and critical infrastructure. This initiative, driv… The Record · Jul 15, 2026 Medium vulnerabilitiesaicybersecurity
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
vulnerability Critical Adobe ColdFusion Vulnerability Exploited in Attacks A critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, has been actively exploited by threat actors shortly after its public disclosure. Adobe released a patch on June 30th, but attackers were observed… SecurityWeek · Jul 7, 2026 Critical CVE-2026-48282vulnerabilitypath traversalcode execution
threat-intel Labcenter Proteus 9 CISA has issued an advisory regarding critical vulnerabilities in Labcenter Proteus 9, a software used in critical infrastructure sectors such as communications, defense industrial base, and energy. These vulnerabilities… CISA Advisories · Jul 7, 2026 High CVE-2026-42953CVE-2026-49033CVE-2026-42958vulnerabilityremote code executioncritical infrastructure
threat-intel Apple Reverses Age-Old Patch Policy to Keep Up With AI Apple is shifting its security patching strategy to a more frequent, independent release model in response to the accelerating pace of AI-driven attacks. Historically, Apple bundled security updates with major OS release… Dark Reading · Jul 2, 2026 High USaizero-daypatching
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
vulnerability Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? This article discusses a security vulnerability discovered in Fortinet’s FortiBleed, a tool designed to securely dispose of sensitive data. A researcher identified a flaw allowing unauthorized access to sensitive data, h… Graham Cluley · Jul 1, 2026 High vulnerabilityfortinetsecurity
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media