vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
vulnerability Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions A critical cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client could allow attackers to execute malicious code through crafted emails, potentially leading to account compromise and data theft. Zimbra… The Hacker News · Jul 11, 2026 High CVE-2025-27915CVE-2023-37580CVE-2024-27443xssvulnerabilityweb client
vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability A vulnerability, dubbed ‘Squidbleed,’ has been discovered in the Squid proxy server, allowing attackers to leak HTTP requests. This flaw stems from a flawed implementation of the HTTP/2 protocol, potentially exposing sen… Schneier on Security · Jul 10, 2026 Medium http2proxyvulnerability
threat-intel URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controllers due to a "credible external security threat." The company has disabled access to affected accounts and is inves… The Hacker News · Jul 10, 2026 High CVE-2023-24489vulnerabilitysecuritycloud
threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers have discovered a new attack technique called ‘HalluSquatting’ that leverages AI assistants’ tendency to fabricate information to create scalable botnets. Attackers register fake repository names, and when us… SecurityWeek · Jul 10, 2026 High aiprompt injectionhallucination
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
data-breach 12 Million Impacted by Data Breach at Japanese Telco KDDI A data breach at Japanese telecom KDDI has impacted over 12 million users due to a zero-day vulnerability exploited by hackers. The attackers gained access to email addresses and passwords, prompting a company-wide passw… SecurityWeek · Jul 9, 2026 High JPdata breachzero-daypassword reset
vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system file… SecurityWeek · Jul 9, 2026 High symlinkaicoding
vulnerability Chrome 150 Update Patches 27 Vulnerabilities Google released Chrome 150, addressing 27 security vulnerabilities, including two critical flaws related to use-after-free bugs. The update represents a significant effort to remediate a substantial number of memory safe… SecurityWeek · Jul 9, 2026 Medium memory-safetyvulnerabilitychrome
threat-intel Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Researchers at AI Now Institute have demonstrated a significant vulnerability in AI coding agents like Anthropic's Claude Code and OpenAI's Codex. By inserting a seemingly harmless binary disguised within a README file,… The Hacker News · Jul 9, 2026 High CVE-2026-39861aicode-injectionsecurity
threat-intel GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositor… The Hacker News · Jul 9, 2026 High CVE-2026-12957symlinkaicode injection
vulnerability Multiples vulnérabilités dans Traefik (09 juillet 2026) Multiple vulnerabilities have been discovered in Traefik, allowing an attacker to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate… CERT-FR · Jul 9, 2026 Medium CVE-2026-65601CVE-2026-65602traefikvulnerabilitysecurity
threat-intel Cash App owner to pay $45 million to settle allegations of lax security Block, Inc. (Cash App's parent company) will pay $45 million to settle allegations of misleading users about Cash App's security and failing to adequately protect them from fraud. The settlement stems from a lack of prop… The Record · Jul 8, 2026 Medium securityfraudmisleading
threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verifie… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability
threat-intel Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection A critical vulnerability, dubbed GitLost, has been identified in GitHub Agentic Workflows, allowing unauthenticated attackers to potentially leak private repository data by injecting prompts into public GitHub Issues. Th… SecurityWeek · Jul 8, 2026 Critical prompt injectionai securityagentic ai