vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
threat-intel ABB Advant Master Online Builder ABB has identified and addressed a vulnerability in its Advant Master Online Builder software, where an incorrect version of the Online Builder could lead to unauthorized DLL loading and potential code execution. The vul… CISA Advisories · Jul 14, 2026 High CVE-2025-13162vulnerabilitydll injectionremote code execution
vulnerability Rockwell Automation 1715-AENTR EtherNet/IP Adapter Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter is vulnerable to a security flaw that could allow unauthorized remote access to a debug port, potentially leading to file deletion, task stopping, memory modification,… CISA Advisories · Jul 14, 2026 High CVE-2026-10577vulnerabilitycveindustrial control systems
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
vulnerability Vulnerability in FIFA’s Network A critical vulnerability in FIFA’s network allowed attackers to potentially gain control of the company’s systems, raising serious concerns about the security of FIFA’s operations and the data it handles. This incident h… Schneier on Security · Jul 14, 2026 High securitynetworkvulnerability
vulnerability ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 14, 2026 Critical strutsdeserializationremote code execution
threat-intel 'Yellow Teams' Are Defining the Future of AI Security A growing trend of ‘yellow teams’ – engineering groups building both attack and defense tools – is emerging as a crucial response to the increasing threat of AI-powered cyberattacks. These teams are using advanced AI mod… Dark Reading · Jul 13, 2026 High aicybersecurityvulnerability
threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
threat-intel New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Researchers have developed MemGhost, an automated tool that can plant false memories in AI assistants by sending a single, carefully crafted email. The tool bypasses existing security measures by exploiting the agents' a… The Hacker News · Jul 13, 2026 High CVE-2025-32711aimemory poisoningemail
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file upl… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
vulnerability Wireshark 4.6.7 Released, (Sat, Jul 11th) Wireshark, a widely used network protocol analyzer, released a security update addressing 12 vulnerabilities and 16 bugs. This update is crucial for maintaining network security and protecting against potential exploits. SANS Internet Storm Center · Jul 11, 2026 Medium wiresharkvulnerabilitynetwork analysis
vulnerability Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions A critical cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client could allow attackers to execute malicious code through crafted emails, potentially leading to account compromise and data theft. Zimbra… The Hacker News · Jul 11, 2026 High CVE-2025-27915CVE-2023-37580CVE-2024-27443xssvulnerabilityweb client
vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability A vulnerability, dubbed ‘Squidbleed,’ has been discovered in the Squid proxy server, allowing attackers to leak HTTP requests. This flaw stems from a flawed implementation of the HTTP/2 protocol, potentially exposing sen… Schneier on Security · Jul 10, 2026 Medium http2proxyvulnerability
threat-intel URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controllers due to a "credible external security threat." The company has disabled access to affected accounts and is inves… The Hacker News · Jul 10, 2026 High CVE-2023-24489vulnerabilitysecuritycloud