threat-intel OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy OVH, a cloud infrastructure provider, is addressing a critical bug in its Januscape hypervisor through a planned system-wide reboot. This follows reports of exploitation attempts targeting the vulnerability, highlighting… The Register · Jul 21, 2026 High CVE-2026-53359hypervisorcloud securityvulnerability
vulnerability ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 21, 2026 Critical apachestrutsvulnerability
vulnerability Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026) Multiple vulnerabilities have been discovered within Tenable Security Center, including remote code execution, SQL injection, and policy bypass. These vulnerabilities, spanning from 2026-06 to 2026-07, allow attackers to… CERT-FR · Jul 21, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitysql injectionremote code execution
threat-intel Attackers pummel critical WordPress vuln to create all sorts of mischief This article covers a range of cybersecurity and technology news, including a vulnerability exploited to create mischief, a Russian phishing campaign mimicking Signal support, and a significant acquisition in the cyberse… The Register · Jul 20, 2026 Medium CVE-2026-63030CVE-2026-60137vulnerabilityphishingransomware
threat-intel 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover A newly discovered exploit chain, dubbed ‘WP2Shell,’ is rapidly being used to compromise millions of WordPress sites. Attackers are chaining together a SQL injection vulnerability (CVE-2026-60137) and a logic flaw in the… Dark Reading · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030sql injectionremote code executionwordpress
threat-intel Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push Ivanti is leveraging large language models (LLMs) to automate vulnerability remediation and discovery, a project initially sparked by the surprising effectiveness of the Claude 4.6 model. Daniel Spicer, Ivanti’s CSO, des… Dark Reading · Jul 20, 2026 Medium CVE-2026-10520llmvulnerabilityautomation
threat-intel 25 Years After Code Red: What the Worm Era Can Teach Us About AI Security Twenty-five years after the Code Red worm, a pivotal moment in cybersecurity history, experts are drawing parallels to the current rush towards AI adoption. The article highlights how Code Red exploited a widespread, oft… Dark Reading · Jul 20, 2026 Medium CHaisecurityvulnerability
threat-intel Malicious cloud customers can bring down the power grid This article covers a range of cybersecurity and technology news, including a report on Russian phishing attacks posing as Signal support, a Microsoft SharePoint vulnerability, and a broader discussion about the evolving… The Register · Jul 20, 2026 Medium IRphishingvulnerabilityransomware
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
vulnerability OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability A denial-of-service vulnerability, dubbed ‘HollowByte,’ in OpenSSL allows attackers to exhaust server memory by crafting a small payload that triggers excessive buffer allocations. This can lead to complete system lockup… SecurityWeek · Jul 20, 2026 High denial-of-servicebuffer overflowmemory exhaustion
threat-intel Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine Russian intelligence services are systematically exploiting internet-connected security cameras across Europe and Ukraine to gather military intelligence, including tracking military transport routes and targeting Ukrain… The Hacker News · Jul 20, 2026 High CVE-2016-7407CVE-2021-39275NLUAcameravulnerabilityespionage
threat-intel Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool Capital One has released its internally developed AI-powered security tool, ‘VulnHunter,’ as open source to address the issue of overwhelming vulnerability scans and improve software supply chain security. The tool proac… SecurityWeek · Jul 20, 2026 Medium vulnerabilityaiopen source
threat-intel Hugging Face Hacked in Autonomous AI Attack Hugging Face, a popular AI collaboration platform, suffered a data breach orchestrated by an autonomous AI agent. The attackers exploited vulnerabilities within their data processing pipeline to gain unauthorized access… SecurityWeek · Jul 20, 2026 High aiautonomousattack
vulnerability Chrome 150 Update Patches Severe Memory Safety Bugs Google released Chrome 150 to address seven memory safety vulnerabilities, including critical use-after-free flaws within components like CameraCapture and GPU. While no exploits have been reported, Google urges users to… SecurityWeek · Jul 20, 2026 High memory-safetyvulnerabilitychrome
threat-intel World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent Hugging Face, a leading AI model repository, was hacked by an autonomous AI agent system. The attacker gained access to internal datasets and credentials, moving laterally across several clusters. While public-facing mod… The Hacker News · Jul 20, 2026 High CHaiautonomous agentsecurity
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
threat-intel ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 20, 2026 High phishingshadowratvulnerability
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Mattermost Server (20 juillet 2026) Multiple vulnerabilities have been discovered in Mattermost Server, requiring users to update to a patched version to mitigate potential security issues. The exact nature of these vulnerabilities is not specified by the… CERT-FR · Jul 20, 2026 Medium mattermostvulnerabilitysecurity update