vulnerability Weintek cMT3092X Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to privilege escalation and credential exposure. A non-privileged user can modify cookies to gain elevated privileges, and user passwords are stored in… CISA Advisories · Jul 23, 2026 High CVE-2026-60134CVE-2026-61892CVE-2026-61886patchplaintextprivilege escalation
vulnerability Panduit IntraVUE Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext st… CISA Advisories · Jul 23, 2026 High CVE-2026-40430CVE-2026-42933CVE-2026-44955industrial control systemsot securitypassword vulnerability
vulnerability Johnson Controls C-CURE 9000 and Victor application server Johnson Controls has issued security advisories regarding critical vulnerabilities in its C-CURE 9000 and Victor application servers, as well as the victor Web application. Exploitation could allow an unauthenticated att… CISA Advisories · Jul 23, 2026 High CVE-2026-21655CVE-2026-21653CVE-2026-34496cve-2026-21653cve-2026-21655cve-2026-34496
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
vulnerability Johnson Controls XAAP Android A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This… CISA Advisories · Jul 23, 2026 High CVE-2026-34490vulnerabilityandroidcleartext storage
vulnerability MZ Automation libIEC61850 MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arb… CISA Advisories · Jul 23, 2026 High CVE-2026-50039CVE-2026-49035CVE-2026-50103iec61850buffer overflowindustrial control systems
threat-intel Swiss train maker tells ransomware crooks to get off at the next stop This article is a collection of security-related news snippets from The Register. It covers a range of topics including a Swiss train maker’s response to ransomware attacks, a security acquisition, ransomware trends, vul… The Register · Jul 23, 2026 Medium ISIRransomwarevulnerabilityjoomla
threat-intel How Synthetic Identity Fraud is Coming for Machine Identities Synthetic identity fraud is a growing threat targeting machine identities, not just human users. Attackers are creating fabricated machine identities – fake accounts that appear legitimate – to gain unauthorized access a… The Hacker News · Jul 23, 2026 High machine identitiessynthetic identity fraudnhis
threat-intel Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers A sophisticated campaign leveraging compromised GitHub repositories is targeting cPanel and WHM servers. Attackers are using malicious GitHub Actions workflows to launch GitHub-hosted runners that scan for vulnerable ser… The Hacker News · Jul 23, 2026 High CVE-2026-41940githubmalwarecpanel
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel End-to-End Encryption and “Going Dark” This analysis examines the ongoing debate surrounding end-to-end encryption (E2EE) and government efforts to restrict its use. The paper argues that the assumption that E2EE completely prevents law enforcement access is… Schneier on Security · Jul 23, 2026 Medium encryptiongoing darksurveillance
data-breach Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses Upbound Group, a consumer finance company operating brands like Rent-A-Center, suffered a data breach resulting in approximately $13 million in fraudulent lease-to-own agreements. The company is investigating the inciden… SecurityWeek · Jul 23, 2026 Medium data breachfinancial servicescybersecurity
threat-intel Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel The Chaos ransomware group is utilizing a new Rust-based remote access Trojan (RAT) called ‘msaRAT’ to infiltrate networks. MsaRAT leverages browser debugging protocols (CDP), specifically Chrome DevTools Protocol, to es… Cisco Talos · Jul 23, 2026 High ransomwarebrowserwebrtc
threat-intel Preview: Cisco Talos at Black Hat USA 2026 Cisco Talos will be at Black Hat USA 2026, showcasing research and demonstrations focused on AI-driven security challenges and threat hunting. They'll cover topics like AI-powered threat actor prompting, securing enterpr… Cisco Talos · Jul 23, 2026 Medium aithreat-huntingsecurity-operations
threat-intel Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts Google has introduced a new selfie video verification method to help users regain access to their accounts if they are locked out or unable to use traditional recovery options like email or phone number. This feature is… The Hacker News · Jul 23, 2026 Medium livenessfacial-recognitionauthentication
threat-intel Assaf Keren Appointed New CISO of Meta Assaf Keren is taking over as Meta's CISO, replacing Guy Rosen after 13 years at the company. He brings a wealth of experience from PayPal and Qualtrics, focusing on building trust and security at scale for Meta’s massiv… SecurityWeek · Jul 23, 2026 Info cisocybersecurityleadership
vulnerability New Check Point Zero-Day Vulnerability Exploited in the Wild A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check… SecurityWeek · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-50751CVE-2024-24919zero-dayauthenticationprivilege escalation
vulnerability Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs A nine-year-old vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows unprivileged local users to gain root access on default Red Hat Enterprise Linux, CentOS Stream, and Amazon Linux installations.… The Hacker News · Jul 23, 2026 High CVE-2026-64600CVE-2026-8933linuxxfskernel
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
threat-intel Brazilian Banking Trojan Actively Spreading in Portugal A long-standing Brazilian banking Trojan, Lampion, is actively targeting Portuguese organizations, leveraging the shared language and cultural connection between Brazilian hackers and Portuguese businesses. The malware,… Dark Reading · Jul 23, 2026 High BRPTESbanking trojanphishinggeofencing