vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
data-breach Hackers steal Lidl customer data from external service provider Lidl, a major European supermarket chain, suffered a data breach after attackers gained access to customer data stored by an external IT service provider. The stolen information included personal details like names, emai… The Record · Jul 13, 2026 Medium DEBENLdata breachcustomer dataretail
threat-intel Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling Meta has filed a patent for an AI system that continuously monitors a user's voice, eye movements, and device usage to analyze their emotional state and provide personalized feedback. The system would track speech patter… The Hacker News · Jul 13, 2026 High aiprivacyemotion-analysis
threat-intel Fresh ATM Crypto Software Bugs: Jackpot or Bust? A researcher, Matt Burch, discovered nine vulnerabilities in CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturer Diebold Nixdorf. These vulnerabilities could allow attackers to bypass encrypti… Dark Reading · Jul 10, 2026 High USatmencryptionjackpotting
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel UK cyber pledge draws only a handful of top firms despite ministerial appeal Despite a strong push from the UK government, only a small number of companies – around 15 out of 350 – signed the Cyber Resilience Pledge. The pledge, designed to improve cybersecurity across the UK economy, requires co… The Record · Jul 7, 2026 Medium UKcybersecuritycyber resiliencevoluntary pledge
threat-intel Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two men were arrested in the Netherlands on suspicion of running a phishing operation targeting credit card details, leading to a significant increase in payment fraud within the country. The Dutch central bank reported… Graham Cluley · Jul 7, 2026 High NLEUphishingcredit card fraudcybercrime
threat-intel The Shift Toward Business-Aligned Risk Management This article discusses the shift towards business-aligned risk management within organizations. Traditional risk assessments, often relying on CVSS scores, can be ineffective without connecting them to tangible business… SecurityWeek · Jul 6, 2026 Medium risk managementcybersecurityvulnerability
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
ransomware Teen suspect in Scattered Spider hacks is extradited to US A 19-year-old man, Peter Stokes, with dual citizenship, has been extradited to the United States to face charges related to his involvement with the Scattered Spider cybercrime group. The investigation centers around a r… The Record · Jul 1, 2026 High USESFIphishingsocial engineeringransomware
threat-intel 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges This article reports the extradition of a 19-year-old, Peter Stokes, known as "Bouquet," from Finland to the United States to face charges related to computer intrusion, fraud, and conspiracy as part of the Scattered Spi… The Hacker News · Jul 1, 2026 High USFIUKsocial engineeringphishinghelp desk
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto
data-breach One Million Passports Leaked Online A database containing nearly a million passports from various countries has been exposed online. The breach occurred due to a vulnerability in an ID verification system used by cannabis dispensaries, highlighting the ris… Schneier on Security · Jun 26, 2026 High passportsdata breachidentity theft
threat-intel SMB cyber readiness: the road to resilience starts here A recent ESET report reveals that while small and medium-sized businesses (SMBs) are increasingly confident in their cybersecurity budgets and preparedness, a significant number still struggle with implementing effective… WeLiveSecurity · Jun 26, 2026 Medium cybersecuritysmbphishing
threat-intel AI and Liability A German court ruled that Google is liable for its AI-generated search summaries, marking a significant shift in how internet publishers are held accountable. The ruling established that AI-generated content, particularl… Schneier on Security · Jun 25, 2026 Medium DEailiabilitygoogle
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication