threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
vulnerability Multiples vulnérabilités dans Mozilla Firefox (15 juillet 2026) Mozilla has announced multiple security vulnerabilities in Firefox, allowing attackers to bypass security policies and potentially cause unspecified security problems. These vulnerabilities require immediate patching to… CERT-FR · Jul 15, 2026 Medium CVE-2026-14906CVE-2026-15718CVE-2026-15719firefoxvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Citrix (15 juillet 2026) Multiple vulnerabilities have been discovered in Citrix products, including potential elevation of privileges, data compromise, and policy bypass. These vulnerabilities affect various Citrix components, requiring immedia… CERT-FR · Jul 15, 2026 Medium CVE-2026-42491CVE-2026-53565CVE-2026-53566vulnerabilitycitrixendpoint
vulnerability Vulnérabilité dans Tenable Nessus Agent (15 juillet 2026) A critical vulnerability has been identified in Tenable Nessus Agent, allowing attackers to execute arbitrary code remotely and bypass security policies. This flaw, CVE-2026-15265, affects older versions of the agent and… CERT-FR · Jul 15, 2026 Critical CVE-2026-15265vulnerabilityremote code executionsecurity policy
vulnerability Multiples vulnérabilités dans Progress LoadMaster (15 juillet 2026) A security bulletin from CERT-FR details multiple vulnerabilities in Progress LoadMaster, allowing attackers to execute arbitrary code remotely and bypass security policies. These flaws affect various versions of the sof… CERT-FR · Jul 15, 2026 Critical CVE-2026-8037CVE-2026-33691vulnerabilityprogressloadmaster
vulnerability Vulnérabilité dans Xen XAPI (15 juillet 2026) A security vulnerability has been identified in Xen XAPI, allowing attackers to bypass security policies. This could lead to unauthorized access and potential system compromise. The vulnerability is being addressed throu… CERT-FR · Jul 15, 2026 Medium CVE-2026-42491xenxapivulnerability
threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability
vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop
vulnerability Microsoft Patches a Record 570 Security Flaws Microsoft released a record 570 security updates for its Windows operating systems and other software, nearly triple the number from last month's Patch Tuesday. The surge in updates is largely due to the increasing use o… Krebs on Security · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayzero-dayvulnerability
vulnerability Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th) Microsoft's July Patch Tuesday release includes a massive 622 vulnerabilities, with a significant number already exploited. Many of these vulnerabilities affect products like Edge and SharePoint, and a notable one – a B… SANS Internet Storm Center · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayvulnerabilitymicrosoft
vulnerability Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Microsoft released a record-breaking 622 security patches this Patch Tuesday, including two actively exploited zero-day vulnerabilities in Active Directory and SharePoint Server. These flaws allow attackers to escalate p… SecurityWeek · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661zero-daypatch tuesdayvulnerability
vulnerability SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data SAP has released security updates to address a critical vulnerability (CVSS 9.9) in its NetWeaver ABAP system, allowing attackers to potentially access or modify data. Two other critical vulnerabilities related to Appro… The Hacker News · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapabapoauth
threat-intel Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads A security vulnerability exists in the Claude for Chrome extension, allowing malicious extensions to trigger unauthorized actions within the user's Gmail, Google Docs, and Calendar accounts. The vulnerability stems from… The Hacker News · Jul 14, 2026 High prompt-injectionextensionvulnerability
vulnerability Adobe Patches Critical ColdFusion Vulnerabilities Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuse… SecurityWeek · Jul 14, 2026 High CVE-2026-48318CVE-2026-48322CVE-2026-48284securitypatchvulnerability
threat-intel Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook? Several states – Illinois, New York, and California – are enacting laws to regulate the deployment of increasingly powerful frontier AI models, requiring developers to establish comprehensive AI frameworks addressing ris… Dark Reading · Jul 14, 2026 High aifrontier-airegulation
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
vulnerability RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Two vulnerabilities in RabbitMQ could allow attackers to steal OAuth secrets, expose tenant data, and potentially take over entire messaging infrastructure. The flaws have been patched, but organizations need to take imm… The Hacker News · Jul 14, 2026 High CVE-2026-57219CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability