vulnerability Siemens CADRA Siemens CADRA is affected by multiple vulnerabilities within the zlib library, primarily stemming from improper input validation and integer overflows. These vulnerabilities could lead to denial-of-service crashes, heap… CISA Advisories · Jul 21, 2026 High CVE-2005-2096CVE-2016-9840CVE-2016-9841zlibvulnerabilitybuffer overflow
threat-intel Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX have discovered a significant vulnerability in five popular open-source Android mobile agent frameworks. These age… The Hacker News · Jul 21, 2026 High CVE-2026-25592CVE-2026-26030CHHOmobile-securityprompt-injectionusb-debugging
threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel N-day is Becoming N-Hour. Patching Faster Won't Save You. The speed at which attackers can now weaponize security patches has dramatically decreased, shrinking the window between a patch's release and a successful exploit. Traditionally, defenders had weeks to react, but now, t… The Hacker News · Jul 21, 2026 High vulnerabilityexploitai
threat-intel CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Andreas Gaetje, CISO at Korber AG, shares his career journey and insights on the evolving role of cybersecurity leadership. He emphasizes the importance of continuous learning and adaptability in a rapidly changing techn… SecurityWeek · Jul 21, 2026 High GEaicybersecurityleadership
threat-intel New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Researchers at Zhejiang University have discovered a method to potentially disrupt power grids using cloud GPUs. Dubbed ‘Bit2Watt,’ the technique involves manipulating a GPU’s power draw – switching between high-intensit… The Hacker News · Jul 21, 2026 High CHgpupower gridcybersecurity
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
threat-intel MIT to Become Hotbed of AI Video Surveillance MIT is investing heavily in a massive AI-powered surveillance system, deploying over 500 cameras across campus and surrounding areas. These cameras will collect detailed data on individuals and objects, including facial… Schneier on Security · Jul 21, 2026 Medium surveillancefacial-recognitionprivacy
threat-intel Anubis menace Coca-Cola via Fairlife The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypt… ZATAZ · Jul 21, 2026 High ransomwaredata breachextortion
threat-intel Coinbase Cartel menace Caterpillar Coinbase Cartel, a ransomware group, is attempting to intimidate Caterpillar with a threat to leak information to the press if the company doesn't respond. They are using a tactic of creating a countdown and threatening… ZATAZ · Jul 21, 2026 Medium ransomwareextortioncybercrime
vulnerability Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data A security researcher discovered a critical vulnerability in Meta's Horizon Managed Solutions platform, allowing an attacker to access sensitive customer support data and manipulate support workflows. Meta patched the is… SecurityWeek · Jul 21, 2026 High idroraccess controlbug bounty
threat-intel Une usurpation cible les services communication An impersonation campaign is targeting businesses by mimicking Damien Bancal and ZATAZ to gain access to internal contacts and initiate a social engineering operation. The attacker uses a fabricated email chain to map ou… ZATAZ · Jul 21, 2026 Medium FRsocial_engineeringimpersonationcybercrime
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
data-breach Clover Health Investments Discloses Data Breach Clover Health Investments suffered a data breach due to a social engineering attack targeting employee accounts. The attackers gained access to member and broker data, but did not reach sensitive corporate financial syst… SecurityWeek · Jul 21, 2026 Medium USdata breachsocial engineeringhealthcare
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
vulnerability Exploitation of ServiceNow Vulnerability Seen Days After Disclosure A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow’s AI platform is being actively exploited in the wild by cybersecurity researchers, not malicious attackers. ServiceNow initially denied active… SecurityWeek · Jul 21, 2026 High CVE-2026-6875remote code executionsandbox escapepatching
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
threat-intel Fuite revendiquée au Rassemblement national ? A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, inclu… ZATAZ · Jul 21, 2026 High FRdata breachsql dumpwordpress
threat-intel Hugging Face frappé par un agent cyber autonome Hugging Face, a leading AI platform, suffered a sophisticated intrusion orchestrated by an autonomous agent, exploiting vulnerabilities in its data processing pipeline. The attacker gained access to internal environments… ZATAZ · Jul 21, 2026 High autonomous agentdata processingcredential theft
vulnerability Zimbra Update Patches Critical Vulnerabilities Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essent… SecurityWeek · Jul 21, 2026 Critical CVE-2026-50055CVE-2026-10631CVE-2026-50054command injectionxssssrf