threat-intel Chick-fil-A Accounts Get Fried in Credential Stuffing Attack Chick-fil-A experienced a data breach due to credential stuffing attacks targeting its loyalty program accounts. Cybercriminals leveraged stolen credentials from various sources to gain unauthorized access, leading to th… SecurityWeek · Jul 23, 2026 Medium credential stuffingdata breachloyalty program
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-lin… Dark Reading · Jul 23, 2026 High JPransomwaresupply chainjapan
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
threat-intel Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Glow, a new AI-powered endpoint security startup, secured $180 million in Series A funding, valuing the company at $1.2 billion. Founded by former Meta and Snowflake executives, Glow focuses on mitigating security risks… SecurityWeek · Jul 22, 2026 Info aiendpoint securitycybersecurity
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
threat-intel Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement dismantled Kratos, a widely used criminal phishing kit, after arresting the developer and taking down over 200 servers. The kit, used by approximately 1,800 customers, was designed to steal… The Hacker News · Jul 22, 2026 High DEUSIDphishingcredential theftmfa bypass
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
threat-intel Une usurpation cible les services communication An impersonation campaign is targeting businesses by mimicking Damien Bancal and ZATAZ to gain access to internal contacts and initiate a social engineering operation. The attacker uses a fabricated email chain to map ou… ZATAZ · Jul 21, 2026 Medium FRsocial_engineeringimpersonationcybercrime
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel New Index Tracks Material Breaches — And Refuses to Add Up the Losses Richard Bird, a former cybersecurity executive, has launched The Hacker in a Hoodie (HIH) Index, a project tracking disclosed material cyber incidents. The index compiles data from SEC filings and news reports, grading t… SecurityWeek · Jul 20, 2026 Medium cybersecuritydata breachloss reporting
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel 1M+ Emails Use Hidden Text to Dupe AI Security Filters Hackers are using a simple, age-old technique – text salting – to bypass modern email security filters, including those powered by AI. Researchers at Barracuda Networks observed over 1 million retail-themed phishing emai… Dark Reading · Jul 16, 2026 Medium phishingtext-saltingai-security
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to over five years in prison for their role in a 2024 attack against Transport for London (TfL). The attack caused… The Record · Jul 16, 2026 High UNcybercrimeransomwaredata breach
supply-chain Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies A cyberattack on Japan's largest cold-chain logistics company, Nichirei Logistics Group, has severely disrupted the country's food supply chain, impacting KFC restaurants, supermarkets, and various food manufacturers. Th… The Record · Jul 15, 2026 High JPcyberattacksupply chainjapan
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch
threat-intel New Webinar: Closing the Approval Gap in AI-Era Ad Tech This article discusses the ‘Approval Gap’ in ad tech, where approved marketing tags can lead to a cascade of third- and fourth-party scripts that security teams haven't vetted. AI is accelerating this issue by increasing… The Hacker News · Jul 15, 2026 Medium ad techprivacycompliance
threat-intel Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal Cribl, a telemetry processing platform, has acquired CardinalOps to bolster its security operations capabilities. This acquisition will allow Cribl customers to map their existing detection rules and security controls to… Dark Reading · Jul 15, 2026 Medium mitre attckdetection engineeringsecurity operations
vulnerability SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data SAP has released security updates to address a critical vulnerability (CVSS 9.9) in its NetWeaver ABAP system, allowing attackers to potentially access or modify data. Two other critical vulnerabilities related to Appro… The Hacker News · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapabapoauth