vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
threat-intel Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors are exploiting a vulnerability in Palo Alto Networks PAN-OS to gain initial access and deploy Qilin ransomware. The vulnerability, CVE-2026-0257, allows unauthenticated remote access, leading to widespread… The Hacker News · Jul 21, 2026 High CVE-2026-0257ransomwarevulnerabilityvpn
data-breach AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert An AI music platform, Suno, experienced a data breach exposing 55 million user accounts. Security expert claims the breach highlights vulnerabilities in the platform's security practices. The incident underscores the gro… The Register · Jul 21, 2026 Medium data breachaisecurity
vulnerability Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra has released patches to address nine security vulnerabilities, including a critical SNMP command injection flaw and several XSS vulnerabilities. These fixes are vital to mitigate potential code execution and email… The Hacker News · Jul 21, 2026 Medium CVE-2026-50055snmpxsscommand-injection
threat-intel Choose Wisely: AI-Generated Coding Risk Varies, A Lot A Secure Code Warrior study revealed that AI-generated code introduces a significant number of vulnerabilities – an average of 15 per codebase – but the risk varies greatly depending on the development framework used. Th… Dark Reading · Jul 21, 2026 Medium aicodevulnerability
threat-intel Intel fortifies Foundry with an actual customer: Fortinet This article covers a range of cybersecurity and technology news, including AMD's challenge to Nvidia's AI compute platform, a Russian phishing campaign mimicking Signal support, and a security acquisition by EQT in the… The Register · Jul 21, 2026 Medium vulnerabilityphishingransomware
threat-intel Empirical Security Raises $25 Million in Series A Funding Cybersecurity startup Empirical secured $25 million in Series A funding to bolster its AI-powered threat prediction and risk management solutions. The company, founded by former Kenna Security executives, aims to address… SecurityWeek · Jul 21, 2026 Info aivulnerabilityrisk management
vulnerability Rockwell Automation FactoryTalk Services Platform Rockwell Automation has issued a security advisory regarding a vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60. An attacker could impersonate an authorized user by bypassing JWT signature validatio… CISA Advisories · Jul 21, 2026 High CVE-2026-10714vulnerabilityftpcisa
vulnerability Rockwell Automation 1734 POINT I/O Rockwell Automation’s 1734 POINT I/O module is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages, potentially causing a system fault and requiring a restart. CISA urges organizatio… CISA Advisories · Jul 21, 2026 Medium CVE-2026-10573USvulnerabilitydenial-of-servicecontrol systems
vulnerability Rockwell Automation ThinManager Rockwell Automation has issued a security advisory regarding a path traversal vulnerability in its ThinManager software. This vulnerability allows an authenticated attacker to write arbitrary files to restricted system d… CISA Advisories · Jul 21, 2026 Critical CVE-2026-11917path traversalicsindustrial control systems
threat-intel Siemens SIDIS Secured SmartPlug Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities stemming from components like OpenSSL, OpenSSH, and libarchive. These vulnerabilities include side-channel attacks, in… CISA Advisories · Jul 21, 2026 High CVE-2022-23303CVE-2019-9494CVE-2022-23304vulnerabilitysupply-chainopen ssl
vulnerability Tycon Systems TPDIN-Monitor-WEB2 Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical authentication bypass flaw, allowing unauthenticated remote attackers to gain full administrative access to the device. This could lead to disr… CISA Advisories · Jul 21, 2026 Critical CVE-2026-61884CVE-2026-55985authentication bypasscwe-288cwe-312
vulnerability Rockwell Automation 1718-AENTR/1719-AENTR Rockwell Automation has issued a security advisory regarding a denial-of-service vulnerability in its 1718-AENTR and 1719-AENTR products. Exploitation could lead to a denial-of-service condition, requiring a power cycle… CISA Advisories · Jul 21, 2026 High CVE-2026-9140USdenial-of-servicecontrol systemsrockwell automation
vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
vulnerability Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Palo Alto Networks has identified vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include cross-site scripting, privilege e… CISA Advisories · Jul 21, 2026 High CVE-2026-0266CVE-2026-0272CVE-2026-0273GEvulnerabilityindustrial control systemscybersecurity
threat-intel N-day is Becoming N-Hour. Patching Faster Won't Save You. The speed at which attackers can now weaponize security patches has dramatically decreased, shrinking the window between a patch's release and a successful exploit. Traditionally, defenders had weeks to react, but now, t… The Hacker News · Jul 21, 2026 High vulnerabilityexploitai
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
threat-intel New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack A new ransomware, ENCFORGE, is targeting AI model files and infrastructure, leveraging a vulnerability in Langflow (CVE-2025-3248) to gain remote code execution. The ransomware, developed by a threat actor linked to a pr… The Hacker News · Jul 21, 2026 High CVE-2025-3248CVE-2026-33017ransomwarelangflowdocker
vulnerability Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released p… The Hacker News · Jul 21, 2026 Critical CVE-2026-6875vulnerabilitycode executionsandbox