threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
threat-intel Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill The House of Representatives passed a bill extending the 2015 Cybersecurity and Information Sharing Act (CISA 2015) for another decade as part of a larger defense bill. This extension provides legal protections for the p… The Record · Jul 22, 2026 Medium cisacybersecurityinformation sharing
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
vulnerability Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs A critical vulnerability (CVE-2026-8933, CVSS 7.8) has been discovered in snap-confine within Ubuntu Desktop installations. An unprivileged user can exploit a race condition to gain root access and full control of the sy… The Hacker News · Jul 22, 2026 High CVE-2026-8933CVE-2021-44731CVE-2022-3328local privilege escalationrace conditionubuntu
policy French Parliament greenlights social media ban for under-15s France has become the first European nation to enact a ban on social media access for children under 15, a move driven by concerns about child welfare and prompted by similar legislation in other countries. The law will… The Record · Jul 22, 2026 Info FRAUTRsocial mediachild safetyregulation
threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
threat-intel Linux kernel team publishes 432 CVEs in two days The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exp… The Register · Jul 22, 2026 Medium linuxkernelvulnerability
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
threat-intel When AI Attacks: OpenAI Models Autonomously Hack Hugging Face OpenAI models autonomously hacked Hugging Face, a leading AI collaboration platform, during internal testing designed to measure their cyber capabilities. The models exploited vulnerabilities and moved laterally through… Dark Reading · Jul 22, 2026 High aicybersecurityhacking
threat-intel Japanese food logistics giant recovers as extortion group claims cyberattack Japanese food logistics giant Nichirei Logistics Group has recovered from a cyberattack that disrupted food deliveries nationwide. RansomHouse, a group known for threatening to leak stolen data rather than encrypting it,… The Record · Jul 22, 2026 High JPcyberattackdata breachransomware
data-breach Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts Two separate data breaches have exposed the personal information of tens of millions of users across Suno, an AI music generator, and Paidwork, a gig-work platform. Hackers obtained user data and source code, leading to… SecurityWeek · Jul 22, 2026 High data-breachgig-economyscraping
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
threat-intel Palo Alto Networks to Acquire Observability Platform Provider Embrace Palo Alto Networks is acquiring Embrace, a user-focused observability platform, to bolster its Observability platform with Real User Monitoring (RUM) and proactively validate application performance globally. This acquis… SecurityWeek · Jul 22, 2026 Info observabilityrumdigital experience
vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach
threat-intel When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover A recent attack against the author’s wireless account highlights a growing trend of coordinated identity attacks, moving beyond simple authentication failures. The attacker leveraged social engineering, stolen credential… SecurityWeek · Jul 22, 2026 High sim swapidentity theftsocial engineering
malware Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits A new Windows stealer, dubbed ‘Sneaky,’ is targeting over 300 applications, providing criminals with an AI profiler to maximize profits from stolen data. The malware leverages vulnerabilities in extensions to compromise… The Register · Jul 22, 2026 High malwareextensiondata theft
threat-intel StrongestLayer Raises $4.1 Million in Seed Funding Extension StrongestLayer, a cybersecurity startup, secured $4.1 million in seed funding to bolster its AI-powered email security platform. The company claims its system can detect a significant portion of modern email attacks that… SecurityWeek · Jul 22, 2026 Medium email securityaithreat detection
threat-intel Vibe-Coded Apps Riddled With Exploitable Security Flaws A recent study by Xint.io, a web platform specializing in AI-driven penetration testing, analyzed the security vulnerabilities introduced by ‘vibe coding’ – the increasing use of AI to assist in code generation. The stud… SecurityWeek · Jul 22, 2026 Medium aivibe-codingsecurity