threat-intel Multiples vulnérabilités dans les produits Elastic (22 juillet 2026) Multiple vulnerabilities have been discovered in Elastic products, including Elasticsearch and Kibana. These vulnerabilities can lead to data integrity compromise, data confidentiality breaches, and denial-of-service att… CERT-FR · Jul 22, 2026 High CVE-2018-17245CVE-2026-42397CVE-2026-49092vulnerabilityssrfelastic
vulnerability Multiples vulnérabilités dans Google Chrome (22 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Windows, Linux, and macOS. Users are advised to consult the official Chrome security update bulletin for availabl… CERT-FR · Jul 22, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415chromevulnerabilitysecurity
threat-intel Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026) Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service. These vulnerabilities are… CERT-FR · Jul 22, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-16349vulnerabilityfirefoxsecurity
vulnerability Multiples vulnérabilités dans GLPI (22 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, allowing an attacker to compromise data confidentiality, data integrity, and bypass security policies. These vulnerabilities affect older versions of the system and… CERT-FR · Jul 22, 2026 Medium CVE-2026-45801CVE-2026-53627CVE-2026-53628glpivulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking products, allowing an attacker to execute arbitrary code, compromise data confidentiality, and bypass security policies. These vulnerabilities affect… CERT-FR · Jul 22, 2026 High CVE-2026-35387CVE-2026-44878CVE-2026-44879vulnerabilitypatchsecurity
threat-intel Ransomware Is Accelerating, But It's Not Because of AI Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victim… Dark Reading · Jul 21, 2026 High USEUransomwarevulnerabilitysupply-chain
threat-intel Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task Large language models (LLMs) are not effectively addressing vulnerability prioritization for application security teams, with a significant number of flagged vulnerabilities proving to be false positives or irrelevant du… Dark Reading · Jul 21, 2026 Medium aivulnerabilityappsec
threat-intel Cisco's open-weight bug busters take on Google and OpenAI This article covers a variety of cybersecurity and technology news items, including Cisco's efforts to compete with Nvidia's AI hardware, a security breach involving Joomla extensions, and various other developments in t… The Register · Jul 21, 2026 Medium securitycybersecurityjoomla
threat-intel AI's cheatin' heart will make you weep This article covers a range of cybersecurity and technology news, including AMD's challenge to Nvidia in AI compute, security vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, an… The Register · Jul 21, 2026 Medium USIRSWcybersecurityphishingransomware
threat-intel DNI nominee Clayton wins Senate panel’s approval The Senate Intelligence Committee has approved Jay Clayton as the next Director of National Intelligence. This approval paves the way for a full Senate vote, potentially enabling the renewal of Section 702 of the FISA Ac… The Record · Jul 21, 2026 Info fisasurveillancenational security
threat-intel Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has finally fixed a significant security flaw in its Hide My Email service, which allowed real email addresses to be exposed in mail logs. The issue stemmed from sending a rejected spam email to a Hide My Email use… The Hacker News · Jul 21, 2026 Medium privacysecurityicloud
threat-intel Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking cybercriminal, known as ‘Trim,’ successfully weaponized publicly available AI language models to create a commercial offensive cybertooling platform. By developing and publishing jailbreaking technique… Dark Reading · Jul 21, 2026 High RUaijailbreakoffensive-security
supply-chain Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains President Trump has signed an executive order requiring defense contractors to map and vet their entire supply chains, including software and materials, to protect national security systems from foreign influence and sub… SecurityWeek · Jul 21, 2026 High supply chainthird party risksbom
threat-intel Cisco Launches Low-Cost AI Models for Source Code Security Cisco has launched Antares, a new small language model (SLM) designed to assist security teams in identifying known vulnerabilities within codebases. Antares is an open-weight model, aiming to provide a cost-effective an… SecurityWeek · Jul 21, 2026 Medium aivulnerabilitycode-security
data-breach Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack Spain has fined 23andMe €2.4 million ($2.7 million) for failing to notify Spanish authorities about a 2023 data breach that impacted over 6.9 million people worldwide. The regulator cited inadequate cybersecurity practic… The Record · Jul 21, 2026 High ESgdprdata breachcybersecurity
threat-intel Kratos phishing-as-a-service kit loses its battle with international law enforcement International law enforcement agencies have taken down a phishing-as-a-service kit operated by Russian threat actors, who were using it to launch attacks mimicking Signal support. The kit exploited vulnerabilities in Joo… The Register · Jul 21, 2026 Medium RUphishingjoomlaopen source
threat-intel AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code A security flaw in AWS Kiro, an AI coding assistant, allowed an attacker to rewrite its configuration file and execute arbitrary code on a developer's machine simply by inserting malicious text into a seemingly innocuous… The Hacker News · Jul 21, 2026 High CVE-2026-10591prompt-injectionai-securitycode-execution
threat-intel Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google has launched Gemini 3.5 Flash Cyber, a specialized AI model designed to rapidly identify and fix software vulnerabilities. This AI model, accessible only to governments and trusted partners through CodeMender, sig… The Hacker News · Jul 21, 2026 High aivulnerabilitycybersecurity
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
threat-intel Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors are exploiting a vulnerability in Palo Alto Networks PAN-OS to gain initial access and deploy Qilin ransomware. The vulnerability, CVE-2026-0257, allows unauthenticated remote access, leading to widespread… The Hacker News · Jul 21, 2026 High CVE-2026-0257ransomwarevulnerabilityvpn