vulnerability ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Jul 17, 2026 Critical log4jjndivulnerability
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel Oak Emerges From Stealth Mode With $60 Million in Funding Israeli cybersecurity startup Oak has secured $60 million in seed funding to develop an AI-powered Identity Operating System, aiming to consolidate fragmented identity governance tools and address the growing challenges… SecurityWeek · Jul 16, 2026 Info ISUSidentity managementaicybersecurity
threat-intel The Hunter's Paradox: Is it time to embrace automated threat hunting? The author, a long-time threat hunting expert, argues that the traditional definition of threat hunting – requiring a human at the center – is becoming outdated due to the sheer volume and velocity of security data. They… Cisco Talos · Jul 16, 2026 Medium threat huntingaiautomation
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
threat-intel China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans China’s military procurement system has suspended or permanently barred over a dozen leading cybersecurity firms since 2024, primarily due to concerns about collusive bidding and not product failures. These companies, in… SecurityWeek · Jul 16, 2026 High CHchinamilitaryprocurement
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans les produits ESET (16 juillet 2026) A denial-of-service vulnerability has been identified in ESET’s endpoint and server security products. Specifically, versions 12.0.x through 12.0.14.0, 12.1.x through 12.1.2.0, 12.2.x through 12.2.9.0, 13.0.x through 13.… CERT-FR · Jul 16, 2026 Medium CVE-2026-6424denial-of-servicevulnerabilityeset
threat-intel Identity Attacks Overtake Exploits as Top Ransomware Cause Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. Despite widespread deployment of MFA (97… Dark Reading · Jul 15, 2026 High ransomwarephishingmfa
threat-intel Windows Bind Link Attacks Can Hide Malware From EDR Tools Researchers at Bitdefender have demonstrated three techniques leveraging Windows’ bind links to evade Endpoint Detection and Response (EDR) tools. These techniques – file-binding, process-binding, and silo-binding – allo… SecurityWeek · Jul 15, 2026 High bind linksedr evasionwindows security
vulnerability Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addres… SecurityWeek · Jul 15, 2026 High CVE-2026-6875CVE-2026-14902CVE-2026-14903vulnerabilitypatchremote code execution
threat-intel SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them… SecurityWeek · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode_injection
threat-intel Recent DShield SIEM Update, (Tue, Jul 14th) The DShield SIEM, a honeypot monitoring system, received a recent update incorporating new features and improved logging capabilities. Specifically, the system now collects TTY logs and integrates Suricata alerts, provid… SANS Internet Storm Center · Jul 15, 2026 Medium honeypotthreat-detectionlog-analysis
vulnerability Vulnérabilité dans Tenable Nessus Agent (15 juillet 2026) A critical vulnerability has been identified in Tenable Nessus Agent, allowing attackers to execute arbitrary code remotely and bypass security policies. This flaw, CVE-2026-15265, affects older versions of the agent and… CERT-FR · Jul 15, 2026 Critical CVE-2026-15265vulnerabilityremote code executionsecurity policy
threat-intel LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts Blackpoint Cyber researchers identified LabubaRAT, a new Rust-based remote access trojan (RAT) that disguises itself as NVIDIA software to gain access to Windows systems. The RAT is highly configurable, utilizing multipl… The Hacker News · Jul 14, 2026 High rustremote access trojanmalware-as-a-service
threat-intel How Pentera Turns AI Security Workflows into Validation Engines Pentera has introduced a new protocol, MCP, to integrate its security validation platform directly into existing AI security workflows. Traditionally, AI security tools relied on fragmented risk signals, leading to guess… The Hacker News · Jul 14, 2026 High aivalidationattack-path
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
threat-intel Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots This article argues that current approaches to AI in Security Operations Centers (SOCs) are fundamentally flawed. Instead of deploying AI to handle the entire alert queue (System 2 work), security teams are often forcing… The Hacker News · Jul 13, 2026 High aisoccognitive
threat-intel Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad… The Hacker News · Jul 11, 2026 High CHINPAcyber espionagelaw enforcementchina
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion