vulnerability RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Two vulnerabilities in RabbitMQ could allow attackers to steal OAuth secrets, expose tenant data, and potentially take over entire messaging infrastructure. The flaws have been patched, but organizations need to take imm… The Hacker News · Jul 14, 2026 High CVE-2026-57219CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability ABB Ability Edgenius ABB has released a security update to address a Linux kernel vulnerability (CVE-2026-31431) in its Ability Edgenius edge computing platform. This vulnerability, known as ‘Copy Fail,’ could allow a local attacker to gain… CISA Advisories · Jul 14, 2026 High CVE-2026-31431linuxvulnerabilityedge computing
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
vulnerability ABB T-MAC Plus ABB has identified and addressed several vulnerabilities in its T-MAC Plus Terminal Management System, primarily related to improper configuration and access controls. These vulnerabilities could allow an attacker to exe… CISA Advisories · Jul 14, 2026 High CVE-2025-14771CVE-2025-14772CVE-2025-14773iisxsscwe-552
vulnerability Rockwell Automation 1715-AENTR EtherNet/IP Adapter Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter is vulnerable to a security flaw that could allow unauthorized remote access to a debug port, potentially leading to file deletion, task stopping, memory modification,… CISA Advisories · Jul 14, 2026 High CVE-2026-10577vulnerabilitycveindustrial control systems
threat-intel ABB Advant Master Online Builder ABB has identified and addressed a vulnerability in its Advant Master Online Builder software, where an incorrect version of the Online Builder could lead to unauthorized DLL loading and potential code execution. The vul… CISA Advisories · Jul 14, 2026 High CVE-2025-13162vulnerabilitydll injectionremote code execution
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
threat-intel How Pentera Turns AI Security Workflows into Validation Engines Pentera has introduced a new protocol, MCP, to integrate its security validation platform directly into existing AI security workflows. Traditionally, AI security tools relied on fragmented risk signals, leading to guess… The Hacker News · Jul 14, 2026 High aivalidationattack-path
threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login aler… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id
vulnerability Vulnerability in FIFA’s Network A critical vulnerability in FIFA’s network allowed attackers to potentially gain control of the company’s systems, raising serious concerns about the security of FIFA’s operations and the data it handles. This incident h… Schneier on Security · Jul 14, 2026 High securitynetworkvulnerability
threat-intel US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Russian state-sponsored APT actors are actively targeting routers worldwide to compromise critical infrastructure. These attacks involve exploiting vulnerabilities and leveraging SNMP to steal device configurations and t… SecurityWeek · Jul 14, 2026 High CVE-2008-4128CVE-2018-0171USAUCAsnmpciscorouter
threat-intel The serpent’s tongue: Luring the Python out of its den This report from Cisco Talos details a growing threat landscape surrounding Python packages, focusing on supply chain attacks leveraging malicious packages installed through package managers like PyPI. The report highlig… Cisco Talos · Jul 14, 2026 High supply chainpythonmalware
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
threat-intel Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads xAI's Grok Build coding CLI has been uploading entire Git repositories, including commit history and sensitive data like API keys and passwords, to a Google Cloud Storage bucket. The issue was discovered by cereblab, who… The Hacker News · Jul 14, 2026 High data-breachgitcredentials
vulnerability Forgotten UEFI shims undermining Secure Boot Researchers at ESET discovered 11 old, Microsoft-signed UEFI shim bootloaders from 2026-02-16 that could bypass UEFI Secure Boot on most systems. These shims, used by various software packages, allowed attackers to deplo… WeLiveSecurity · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797CVE-2020-10713uefisecure bootrevocation
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy