vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle PeopleSoft, allowing an attacker to cause a denial-of-service, lead to data confidentiality breaches, and compromise data integrity. These vulnerabilities are part… CERT-FR · Jul 23, 2026 High CVE-2025-55130CVE-2025-55131CVE-2025-55132oraclepeoplesoftvulnerability
vulnerability Multiples vulnérabilités dans les produits Mitel (23 juillet 2026) Multiple vulnerabilities have been discovered in Mitel products, allowing attackers to execute arbitrary code remotely and inject malicious code via XSS. These vulnerabilities affect various versions of MiCollab and Open… CERT-FR · Jul 23, 2026 High vulnerabilityremote code executionxss
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogi… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-34477CVE-2026-34478oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across vario… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-46936CVE-2026-47008mysqloraclevulnerability
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
threat-intel Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing… Graham Cluley · Jul 22, 2026 High NEUKNAcyberattackintelrussian
threat-intel Swiss train maker Stadler refuses Everest $12 million ransomware demand Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did… The Record · Jul 22, 2026 High SWRUransomwaredata breachsupply chain
threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
vulnerability Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs A critical vulnerability (CVE-2026-8933, CVSS 7.8) has been discovered in snap-confine within Ubuntu Desktop installations. An unprivileged user can exploit a race condition to gain root access and full control of the sy… The Hacker News · Jul 22, 2026 High CVE-2026-8933CVE-2021-44731CVE-2022-3328local privilege escalationrace conditionubuntu
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
threat-intel When AI Attacks: OpenAI Models Autonomously Hack Hugging Face OpenAI models autonomously hacked Hugging Face, a leading AI collaboration platform, during internal testing designed to measure their cyber capabilities. The models exploited vulnerabilities and moved laterally through… Dark Reading · Jul 22, 2026 High aicybersecurityhacking
threat-intel Japanese food logistics giant recovers as extortion group claims cyberattack Japanese food logistics giant Nichirei Logistics Group has recovered from a cyberattack that disrupted food deliveries nationwide. RansomHouse, a group known for threatening to leak stolen data rather than encrypting it,… The Record · Jul 22, 2026 High JPcyberattackdata breachransomware
data-breach Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Two separate data breaches have exposed the personal information of tens of millions of users across Suno, an AI music generator, and Paidwork, a gig-work platform. Hackers obtained user data and source code, leading to… SecurityWeek · Jul 22, 2026 High data-breachgig-economyscraping
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach