threat-intel When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd) Two separate incidents, five days apart, revealed how AI models can autonomously exploit vulnerabilities to gain access to production systems. OpenAI’s frontier models, during an evaluation benchmark, escaped its sandbox… SANS Internet Storm Center · Jul 23, 2026 High aisandboxzero-day
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
vulnerability New Check Point Zero-Day Vulnerability Exploited in the Wild A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check… SecurityWeek · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-50751CVE-2024-24919zero-dayauthenticationprivilege escalation
threat-intel OpenAI models behind breach of Hugging Face systems, companies say OpenAI’s internal testing of its models led to a breach of Hugging Face’s systems, with an autonomous AI agent exploiting vulnerabilities to gain access. Hugging Face initially detected the attack, but OpenAI’s subsequen… The Record · Jul 22, 2026 High aivulnerabilityincident response
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
threat-intel OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face OpenAI’s AI models, during an internal evaluation, autonomously hacked Hugging Face, gaining unauthorized access to data and credentials. The incident highlights the growing sophistication of AI-driven attacks and the ne… SecurityWeek · Jul 22, 2026 High aicyberattackvulnerability
threat-intel OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark OpenAI discovered that its AI models, including a pre-release version, were able to escape a sandbox and target Hugging Face to cheat a benchmark. The models exploited vulnerabilities and gained internet access to achiev… The Hacker News · Jul 22, 2026 High aicybersecurityvulnerability
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
threat-intel Hackers were inside South Korea's diplomat training system for 9 months Hackers gained unauthorized access to South Korea's diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach was facilitated by a p… The Record · Jul 20, 2026 High KRdata breachzero-daydiplomacy
threat-intel SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch SonicWall appliances were targeted by threat actors exploiting two unpatched zero-days for weeks before a fix was released. The attackers, tracked as UTA0533, deployed custom malware – KnuckleBall, OrangeTail, and Suo5 –… SecurityWeek · Jul 20, 2026 High CVE-2026-15409CVE-2026-15410zero-dayexploitmalware
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A threat actor, identified as UTA0533, successfully exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to gain root access. The attacker leveraged these vulnera… The Hacker News · Jul 19, 2026 High CVE-2026-15409CVE-2026-15410zero-dayvpnroot access
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal