threat-intel Siemens SICAM 8 Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of servi… CISA Advisories · Jul 16, 2026 High CVE-2026-54798CVE-2026-54799CVE-2026-54800vulnerabilityfirmwareindustrial control systems
vulnerability AutomationDirect Productivity Suite AutomationDirect Productivity Suite versions 4.6.2.2 and earlier are vulnerable to multiple out-of-bounds read and write vulnerabilities, potentially leading to kernel memory corruption, privilege escalation, system inst… CISA Advisories · Jul 16, 2026 High CVE-2026-60063CVE-2026-61389CVE-2026-60140cvevulnerabilityioctl
threat-intel Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to over five years in prison for their role in a 2024 attack against Transport for London (TfL). The attack caused… The Record · Jul 16, 2026 High UNcybercrimeransomwaredata breach
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Researchers at Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have discovered a new attack method called Agent Data Injection (ADI) that can manipulate AI agents by subtly corruptin… The Hacker News · Jul 16, 2026 High CVE-2025-32711prompt-injectiondata-exfiltrationai-security
threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
vulnerability Splunk, Zoom Patch Critical Vulnerabilities Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti… SecurityWeek · Jul 16, 2026 High CVE-2026-20296CVE-2026-20297CVE-2026-20298vulnerabilitypatchsecurity
threat-intel AI Can Find Bugs, But Human Knowledge Still Proves Them AI tools are increasingly being used in security testing, offering benefits like rapid code analysis and payload generation. However, the key challenge remains that AI-generated findings often lack sufficient validation… The Hacker News · Jul 16, 2026 High aivulnerabilitysecurity
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
threat-intel China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans China’s military procurement system has suspended or permanently barred over a dozen leading cybersecurity firms since 2024, primarily due to concerns about collusive bidding and not product failures. These companies, in… SecurityWeek · Jul 16, 2026 High CHchinamilitaryprocurement
threat-intel OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol OpenAI has developed GPT-Red, an automated red-teaming model, to proactively identify and mitigate prompt injection vulnerabilities in its large language models, particularly GPT-5.6 Sol. This model, trained through self… The Hacker News · Jul 16, 2026 High prompt injectionred teamingai security
threat-intel Old UEFI Shims Expose Systems to Secure Boot Bypass A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating ba… SecurityWeek · Jul 16, 2026 High CVE-2026-8863CVE-2026-10797uefisecure bootvulnerability
vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
threat-intel Police Disrupt a €140M Cyber Fraud Ring in Spain Spanish police disrupted a €140 million cyber fraud ring operating across multiple countries, involving over 70 individuals and a complex network of money laundering. The operation involved sophisticated techniques like… Dark Reading · Jul 16, 2026 High SPPOPAcybercrimefraudmoney laundering
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits Splunk (16 juillet 2026) Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten… CERT-FR · Jul 16, 2026 High CVE-2025-30204CVE-2025-47913CVE-2025-61726vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits F5 (16 juillet 2026) Multiple vulnerabilities have been discovered in F5 products, including BIG-IP, WAF, and NGINX. These vulnerabilities could allow an attacker to achieve remote code execution, denial of service, and data confidentiality… CERT-FR · Jul 16, 2026 High CVE-2026-42533CVE-2026-46333CVE-2026-52865securityvulnerabilitypatch
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub