threat-intel Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Ge… Graham Cluley · Jul 17, 2026 Medium androidgeminilock screen
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
vulnerability OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process dur… The Hacker News · Jul 17, 2026 High CVE-2025-66199CVE-2026-34183memory-exhaustiondostls
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
threat-intel The Real AI Threat Is Blind Trust A recent attack exploited a vulnerability in AI systems, allowing attackers to manipulate one AI agent into generating instructions for another, leading to unauthorized fund transfers. This highlights a growing risk as A… Dark Reading · Jul 17, 2026 High NOaiautomationgovernance
threat-intel Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle, a voluntary initiative aimed at coordinating vulnerability response across critical infrastructure sectors, leveraging AI to accelerate the patching process. However, the initiative i… Dark Reading · Jul 17, 2026 Medium vulnerabilityaicybersecurity
threat-intel Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A collaborative research effort between Palo Alto Networks and Siemens has uncovered a critical, chained exploit within the Siemens ROX II operational technology (OT) switches. The vulnerability chain consists of three z… Palo Alto Unit 42 · Jul 17, 2026 Critical CVE-2025-40948CVE-2025-40947CVE-2025-40949otvulnerabilitycommand-injection
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
vulnerability ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Jul 17, 2026 Critical log4jjndivulnerability
vulnerability Multiples vulnérabilités dans Microsoft Windows (17 juillet 2026) Microsoft has announced multiple vulnerabilities across various versions of Windows, including Windows 10 and 11. These vulnerabilities could allow attackers to execute arbitrary code remotely, elevate privileges, and co… CERT-FR · Jul 17, 2026 High CVE-2026-56171CVE-2026-58598CVE-2026-58643windowsvulnerabilitypatch
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (17 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. These vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The affected products range from deskt… CERT-FR · Jul 17, 2026 High CVE-2023-53995CVE-2025-68324CVE-2025-71089vulnerabilitylinuxsecurity
threat-intel Multiples vulnérabilités dans le noyau Linux d'Ubuntu (17 juillet 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, remote denial of service, and data confidentiality compromise. The vulnerabilitie… CERT-FR · Jul 17, 2026 High CVE-2021-47117CVE-2021-47202CVE-2022-48816linuxkernelvulnerability
threat-intel Multiples vulnérabilités dans les produits IBM (17 juillet 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service vulnerabilities. Several CVEs have been assigned, covering a wide range of IBM p… CERT-FR · Jul 17, 2026 High CVE-2020-28500CVE-2020-7760CVE-2020-8203vulnerabilitysupply-chainremote-code-execution
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (17 juillet 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities can lead to arbitrary code execution, privilege escalation, and a denial-of-service attack. Red Hat has released security adv… CERT-FR · Jul 17, 2026 High CVE-2025-38653CVE-2025-68183CVE-2025-68724linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans Google Chrome (17 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser. The exact nature of the security issue is not specified by the publisher, but users are advised to update to the la… CERT-FR · Jul 17, 2026 Medium CVE-2026-15899CVE-2026-15900CVE-2026-15901vulnerabilitychromesecurity
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft products, primarily within SharePoint, allowing attackers to compromise data confidentiality and bypass security policies. Microsoft has released security bullet… CERT-FR · Jul 17, 2026 Medium CVE-2026-56171CVE-2026-62826sharepointvulnerabilitymicrosoft
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
threat-intel Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack Two young British hackers, Owen Flowers and Thalha Jubair, were convicted and sentenced to five and a half years for a sophisticated attack on Transport for London (TfL), resulting in significant disruption and financial… The Hacker News · Jul 16, 2026 High cybercrimehackvulnerability
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking