threat-intel Anubis menace Coca-Cola via Fairlife The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypt… ZATAZ · Jul 21, 2026 High ransomwaredata breachextortion
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
threat-intel Fuite revendiquée au Rassemblement national ? A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, inclu… ZATAZ · Jul 21, 2026 High FRdata breachsql dumpwordpress
threat-intel Hugging Face frappé par un agent cyber autonome Hugging Face, a leading AI platform, suffered a sophisticated intrusion orchestrated by an autonomous agent, exploiting vulnerabilities in its data processing pipeline. The attacker gained access to internal environments… ZATAZ · Jul 21, 2026 High autonomous agentdata processingcredential theft
threat-intel New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack A new ransomware, ENCFORGE, is targeting AI model files and infrastructure, leveraging a vulnerability in Langflow (CVE-2025-3248) to gain remote code execution. The ransomware, developed by a threat actor linked to a pr… The Hacker News · Jul 21, 2026 High CVE-2025-3248CVE-2026-33017ransomwarelangflowdocker
threat-intel OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy OVH, a cloud infrastructure provider, is addressing a critical bug in its Januscape hypervisor through a planned system-wide reboot. This follows reports of exploitation attempts targeting the vulnerability, highlighting… The Register · Jul 21, 2026 High CVE-2026-53359hypervisorcloud securityvulnerability
vulnerability Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026) Multiple vulnerabilities have been discovered within Tenable Security Center, including remote code execution, SQL injection, and policy bypass. These vulnerabilities, spanning from 2026-06 to 2026-07, allow attackers to… CERT-FR · Jul 21, 2026 High CVE-2025-11187CVE-2025-14179CVE-2025-15467vulnerabilitysql injectionremote code execution
threat-intel 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover A newly discovered exploit chain, dubbed ‘WP2Shell,’ is rapidly being used to compromise millions of WordPress sites. Attackers are chaining together a SQL injection vulnerability (CVE-2026-60137) and a logic flaw in the… Dark Reading · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030sql injectionremote code executionwordpress
threat-intel CISOs Feel the Heat Over AI Risk CISOs are facing increased pressure and job insecurity due to the rapid and often chaotic adoption of AI within companies. A recent Splunk survey revealed that 26% of top security executives are considering leaving their… Dark Reading · Jul 20, 2026 High aicybersecurityrisk
threat-intel Attackers Combo Up Evasion Tactics for BEC Phishing Attackers are employing increasingly sophisticated evasion techniques to deliver BEC phishing attacks, utilizing a multi-stage process involving disguised font files, Lua interpreters, and fileless execution to bypass en… Dark Reading · Jul 20, 2026 High phishingbecevasion
threat-intel FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware A sophisticated campaign dubbed FakeGit has leveraged nearly 7,600 malicious GitHub repositories to spread SmartLoader malware, utilizing AI agents to discover these fake repositories and execute the attack. The campaign… The Hacker News · Jul 20, 2026 High aigithubmalware
threat-intel India says allegedly leaked nuclear plant files pose no safety risk A cybercrime group, World Leaks (formerly Hunters International ransomware), has allegedly leaked thousands of files related to India's Kudankulam Nuclear Power Plant, claiming they originated from a breach involving Rel… The Record · Jul 20, 2026 High INcybercrimedata breachnuclear
threat-intel Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A cybercriminal, utilizing AI coding tools and a sophisticated pipeline, exposed a comprehensive phishing toolkit targeting Mexican users and beyond. The operator, likely leveraging LLMs and tools like Coderrr, created a… The Hacker News · Jul 20, 2026 High CVE-2025-33053CVE-2026-21513CVE-2025-24054MXUSDEphishingwebdavai
threat-intel Hackers were inside South Korea's diplomat training system for 9 months Hackers gained unauthorized access to South Korea's diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach was facilitated by a p… The Record · Jul 20, 2026 High KRdata breachzero-daydiplomacy
threat-intel Romania races to restore land registry after cyberattack disrupts property market A major cyberattack disrupted Romania's land registry system, causing a standstill in property transactions and delaying a planned increase in property taxes. The attack, attributed to a threat actor named ByteToBreach,… The Record · Jul 20, 2026 High ROcyberattackland registryproperty
threat-intel HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A sophisticated espionage implant, dubbed HollowGraph, is using a hijacked Microsoft 365 calendar as its command and control channel to steal data and deliver instructions. The malware, linked to the Iranian threat group… The Hacker News · Jul 20, 2026 High ISIRespionagecommand-and-controlmicrosoft 365