supply-chain Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains President Trump has signed an executive order requiring defense contractors to map and vet their entire supply chains, including software and materials, to protect national security systems from foreign influence and sub… SecurityWeek · Jul 21, 2026 High supply chainthird party risksbom
data-breach Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack Spain has fined 23andMe €2.4 million ($2.7 million) for failing to notify Spanish authorities about a 2023 data breach that impacted over 6.9 million people worldwide. The regulator cited inadequate cybersecurity practic… The Record · Jul 21, 2026 High ESgdprdata breachcybersecurity
threat-intel AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code A security flaw in AWS Kiro, an AI coding assistant, allowed an attacker to rewrite its configuration file and execute arbitrary code on a developer's machine simply by inserting malicious text into a seemingly innocuous… The Hacker News · Jul 21, 2026 High CVE-2026-10591prompt-injectionai-securitycode-execution
threat-intel Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google has launched Gemini 3.5 Flash Cyber, a specialized AI model designed to rapidly identify and fix software vulnerabilities. This AI model, accessible only to governments and trusted partners through CodeMender, sig… The Hacker News · Jul 21, 2026 High aivulnerabilitycybersecurity
threat-intel Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors are exploiting a vulnerability in Palo Alto Networks PAN-OS to gain initial access and deploy Qilin ransomware. The vulnerability, CVE-2026-0257, allows unauthenticated remote access, leading to widespread… The Hacker News · Jul 21, 2026 High CVE-2026-0257ransomwarevulnerabilityvpn
threat-intel A new extortion cocktail: office printers, small ransoms, and BitLocker Two separate incidents – one in Colombia and another in Mexico – highlight a concerning trend of attackers leveraging misconfigured systems and built-in Microsoft tools to deploy BitLocker encryption and demand ransom pa… Securelist · Jul 21, 2026 High COMXransomwarebitlockerrdp
threat-intel Siemens SIDIS Secured SmartPlug Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities stemming from components like OpenSSL, OpenSSH, and libarchive. These vulnerabilities include side-channel attacks, in… CISA Advisories · Jul 21, 2026 High CVE-2022-23303CVE-2019-9494CVE-2022-23304vulnerabilitysupply-chainopen ssl
vulnerability Rockwell Automation FactoryTalk Services Platform Rockwell Automation has issued a security advisory regarding a vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60. An attacker could impersonate an authorized user by bypassing JWT signature validatio… CISA Advisories · Jul 21, 2026 High CVE-2026-10714vulnerabilityftpcisa
vulnerability Rockwell Automation Studio 5000 Logix Designer Rockwell Automation has issued security advisories regarding multiple vulnerabilities in Studio 5000 Logix Designer, primarily due to path traversal and unquoted search path issues. These vulnerabilities could allow a lo… CISA Advisories · Jul 21, 2026 High CVE-2026-9108CVE-2026-9127CVE-2026-9128path traversalunquoted search pathremote code execution
vulnerability Rockwell Automation 1718-AENTR/1719-AENTR Rockwell Automation has issued a security advisory regarding a denial-of-service vulnerability in its 1718-AENTR and 1719-AENTR products. Exploitation could lead to a denial-of-service condition, requiring a power cycle… CISA Advisories · Jul 21, 2026 High CVE-2026-9140USdenial-of-servicecontrol systemsrockwell automation
vulnerability Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW Palo Alto Networks has identified vulnerabilities in PAN-OS software affecting Siemens RUGGEDCOM APE1808 devices when used with their Virtual NGFW solution. These vulnerabilities include cross-site scripting, privilege e… CISA Advisories · Jul 21, 2026 High CVE-2026-0266CVE-2026-0272CVE-2026-0273GEvulnerabilityindustrial control systemscybersecurity
vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
threat-intel Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX have discovered a significant vulnerability in five popular open-source Android mobile agent frameworks. These age… The Hacker News · Jul 21, 2026 High CVE-2026-25592CVE-2026-26030CHHOmobile-securityprompt-injectionusb-debugging
threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel N-day is Becoming N-Hour. Patching Faster Won't Save You. The speed at which attackers can now weaponize security patches has dramatically decreased, shrinking the window between a patch's release and a successful exploit. Traditionally, defenders had weeks to react, but now, t… The Hacker News · Jul 21, 2026 High vulnerabilityexploitai
threat-intel CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Andreas Gaetje, CISO at Korber AG, shares his career journey and insights on the evolving role of cybersecurity leadership. He emphasizes the importance of continuous learning and adaptability in a rapidly changing techn… SecurityWeek · Jul 21, 2026 High GEaicybersecurityleadership
threat-intel New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Researchers at Zhejiang University have discovered a method to potentially disrupt power grids using cloud GPUs. Dubbed ‘Bit2Watt,’ the technique involves manipulating a GPU’s power draw – switching between high-intensit… The Hacker News · Jul 21, 2026 High CHgpupower gridcybersecurity
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
threat-intel Anubis menace Coca-Cola via Fairlife The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypt… ZATAZ · Jul 21, 2026 High ransomwaredata breachextortion
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty