vulnerability Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape Broadcom has released security updates to address three critical vulnerabilities in VMware products, including a virtual machine escape. These flaws allow for authentication bypass, code execution, and potentially unauth… The Hacker News · Jul 29, 2026 High CVE-2026-59309CVE-2026-59310CVE-2026-47876vulnerabilitypatchsecurity
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day
vulnerability Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms A critical vulnerability (CVE-2026-59726) in the Ruflo AI agent platform allows unauthenticated attackers to gain full remote code execution, access provider API keys, and even tamper with the AI's memory, potentially un… Dark Reading · Jul 29, 2026 Critical CVE-2026-59726aimemory corruptionremote code execution
threat-intel Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems Iranian-linked cyber actors, believed to be part of the CyberAv3ngers group, are suspected of launching attacks against Minnesota water systems. This indicates a broader trend of state-sponsored cyber activity targeting… The Register · Jul 29, 2026 High IRcyberattackcritical infrastructurestate-sponsored
threat-intel Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline A coordinated cyberattack targeted over 30 community water systems in Minnesota, leading to operational disruptions and communications failures. While the exact number of compromised systems remains unclear, the attacks… The Hacker News · Jul 29, 2026 High UNcritical infrastructureindustrial control systemscyberattack
threat-intel Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments A nine-year-old fraud campaign, originating in 2017, has been uncovered by cybersecurity firm F6, involving the creation of clone websites mimicking major Russian companies to steal advance payments from international cl… The Hacker News · Jul 29, 2026 High RUAZfraudclone websiteadvance payment
threat-intel US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security The U.S. Federal Communications Commission is implementing a ban on new imports of foreign-made humanoid robots and power inverters, primarily targeting China due to national security concerns. This move follows a series… SecurityWeek · Jul 29, 2026 High CHUSchinaroboticsnational security
threat-intel Mate Security Raises $35 Million for Agentic SOC Mate Security, an Israeli AI-powered SOC startup, has secured $35 million in Series A funding to bolster its agentic platform and expand its operations. The company’s platform utilizes AI to create dynamic security conte… SecurityWeek · Jul 29, 2026 Info ILaisocsecurity
threat-intel Russia accuses Telegram founder of aiding terrorism, seeks international arrest Russia has formally accused Telegram founder Pavel Durov of aiding terrorism, seeking an international arrest warrant due to allegations that the messaging app was used by Ukrainian intelligence to organize terrorist att… The Record · Jul 29, 2026 High RUUKFRrussiatelegramukraine
threat-intel ThreatLocker Raises $190 Million in Series F Funding ThreatLocker, a zero trust endpoint security company, secured $190 million in Series F funding, significantly increasing its valuation to $1.6 billion. This investment will fuel the company’s expansion plans, including a… SecurityWeek · Jul 29, 2026 Medium zero trustendpoint securityfunding
threat-intel Mythos Asks the Right Question. It Doesn't Answer It. The article argues that AI-powered exploit discovery tools like Mythos are compressing the time between vulnerability disclosure and exploitation, but the real problem isn't faster patching – it's that most security team… The Hacker News · Jul 29, 2026 High vulnerabilitythreat-intelai
threat-intel Cyberattack hits Angola’s largest telco hours before landmark stock debut Angola’s largest telecommunications operator, Unitel, experienced a significant cyberattack that disrupted services nationwide, occurring just hours before its landmark stock market debut. The attack appears to have been… The Record · Jul 29, 2026 High AOcyberattacktelecomipo
threat-intel 2026 Minimum Elements for a Software Bill of Materials (SBOM) The U.S. government, alongside international partners, released updated guidance on Software Bill of Materials (SBOMs). This new standard, effective as of 2026, outlines the essential components needed for SBOMs, aiming… CISA Advisories · Jul 29, 2026 Info sbomsoftware securitysupply chain
vulnerability Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Researchers at Nebula Security discovered a vulnerability in Firefox's JIT compiler that allows a single malicious webpage visit to compromise the browser, including Tor Browser. This vulnerability, CVE-2026-10702, can b… The Hacker News · Jul 29, 2026 High CVE-2026-10702CVE-2026-43499jitsifirefoxexploit
vulnerability Critical VM Escape Vulnerability Patched in VMware ESXi VMware has released patches to address several critical vulnerabilities in its ESXi, vCenter, Workstation, and Fusion products. These flaws could allow attackers to execute code on the host, bypass authentication, or cau… SecurityWeek · Jul 29, 2026 Critical CVE-2026-47876CVE-2026-59309CVE-2026-59310vulnerabilitypatchsecurity
threat-intel 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack A recent study reveals that 73% of organizations aren't fully prepared to withstand a major cyberattack, despite having incident response plans and security tools. The core issue isn't simply having these capabilities, b… The Hacker News · Jul 29, 2026 High incident responsecybersecurityvulnerability
vulnerability Long-Lived Vulnerability in Microsoft Secure Boot A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsi… Schneier on Security · Jul 29, 2026 High firmwareshimuefi
threat-intel Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity Russia has charged Telegram founder Pavel Durov with aiding terrorist activity, alleging that the platform was used by Ukrainian special services and terrorist organizations to plan attacks and facilitate cybercrime with… The Hacker News · Jul 29, 2026 High RUUArussiaukraineintelligence
threat-intel US, Australia Release OT Isolation Guidance for Critical Infrastructure The US cybersecurity agency CISA and Australia’s ACSC have jointly released guidance, ‘CI Fortify,’ to help critical infrastructure organizations isolate vital Operational Technology (OT) systems and supporting networks.… SecurityWeek · Jul 29, 2026 Medium USAUcritical infrastructureot securitycyber resilience
threat-intel Pages piégées à Saint-Denis, le test avant l’opération d’influence ? A French swimming pool website was infiltrated in June 2026 by pirates, who have since been altering pages to test the pool's defenses and gather intelligence. The attackers are using the website's modification patterns… ZATAZ · Jul 29, 2026 High FRcyber espionagereconnaissancedisinformation