threat-intel SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch SonicWall appliances were targeted by threat actors exploiting two unpatched zero-days for weeks before a fix was released. The attackers, tracked as UTA0533, deployed custom malware – KnuckleBall, OrangeTail, and Suo5 –… SecurityWeek · Jul 20, 2026 High CVE-2026-15409CVE-2026-15410zero-dayexploitmalware
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
vulnerability OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability A denial-of-service vulnerability, dubbed ‘HollowByte,’ in OpenSSL allows attackers to exhaust server memory by crafting a small payload that triggers excessive buffer allocations. This can lead to complete system lockup… SecurityWeek · Jul 20, 2026 High denial-of-servicebuffer overflowmemory exhaustion
threat-intel Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine Russian intelligence services are systematically exploiting internet-connected security cameras across Europe and Ukraine to gather military intelligence, including tracking military transport routes and targeting Ukrain… The Hacker News · Jul 20, 2026 High CVE-2016-7407CVE-2021-39275NLUAcameravulnerabilityespionage
threat-intel Mythos Didn't Break Your Security Program. Your Exposure Window Could. The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actua… The Hacker News · Jul 20, 2026 High vulnerabilitiesexposure windowattack path analysis
data-breach Ernst & Young Data Breach Affects Personal, Financial Information Ernst & Young (EY) experienced a data breach affecting the personal and financial information of its clients due to a vulnerability in a third-party service management platform. The breach, discovered in April, exposed s… SecurityWeek · Jul 20, 2026 High data breachtaxsocial security
threat-intel Software provider to more than 2,000 US hospitals says hackers stole employee and customer data Craneware, a UK-based software provider used by over 2,000 U.S. hospitals, has been hacked, resulting in the theft of employee, customer, and partner data. The company has contained the breach and reported it to law enfo… The Record · Jul 20, 2026 High UKUShealthcaredata breachcyberattack
threat-intel Hugging Face Hacked in Autonomous AI Attack Hugging Face, a popular AI collaboration platform, suffered a data breach orchestrated by an autonomous AI agent. The attackers exploited vulnerabilities within their data processing pipeline to gain unauthorized access… SecurityWeek · Jul 20, 2026 High aiautonomousattack
vulnerability New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction A vulnerability (CVE-2026-14266) in 7-Zip’s XZ archive handling allows an attacker to execute code on a victim machine by crafting a malicious XZ archive. The vulnerability stems from a buffer overflow when processing XZ… The Hacker News · Jul 20, 2026 High CVE-2026-14266CVE-2026-48095buffer overflowremote code executionarchive handling
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
vulnerability Chrome 150 Update Patches Severe Memory Safety Bugs Google released Chrome 150 to address seven memory safety vulnerabilities, including critical use-after-free flaws within components like CameraCapture and GPU. While no exploits have been reported, Google urges users to… SecurityWeek · Jul 20, 2026 High memory-safetyvulnerabilitychrome
threat-intel World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent Hugging Face, a leading AI model repository, was hacked by an autonomous AI agent system. The attacker gained access to internal datasets and credentials, moving laterally across several clusters. While public-facing mod… The Hacker News · Jul 20, 2026 High CHaiautonomous agentsecurity
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
threat-intel ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 20, 2026 High phishingshadowratvulnerability
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A threat actor, identified as UTA0533, successfully exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to gain root access. The attacker leveraged these vulnera… The Hacker News · Jul 19, 2026 High CVE-2026-15409CVE-2026-15410zero-dayvpnroot access