threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
vulnerability Splunk, Zoom Patch Critical Vulnerabilities Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti… SecurityWeek · Jul 16, 2026 High CVE-2026-20296CVE-2026-20297CVE-2026-20298vulnerabilitypatchsecurity
threat-intel AI Can Find Bugs, But Human Knowledge Still Proves Them AI tools are increasingly being used in security testing, offering benefits like rapid code analysis and payload generation. However, the key challenge remains that AI-generated findings often lack sufficient validation… The Hacker News · Jul 16, 2026 High aivulnerabilitysecurity
threat-intel The Hunter's Paradox: Is it time to embrace automated threat hunting? The author, a long-time threat hunting expert, argues that the traditional definition of threat hunting – requiring a human at the center – is becoming outdated due to the sheer volume and velocity of security data. They… Cisco Talos · Jul 16, 2026 Medium threat huntingaiautomation
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability
threat-intel Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers This episode of Smashing Security explores a series of unusual events, primarily focusing on a deep dive into a massive leak of internal communications from the Conti ransomware gang. The podcast details how the chats, f… Graham Cluley · Jul 16, 2026 Medium INransomwareremote-controle-rickshaw
threat-intel China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans China’s military procurement system has suspended or permanently barred over a dozen leading cybersecurity firms since 2024, primarily due to concerns about collusive bidding and not product failures. These companies, in… SecurityWeek · Jul 16, 2026 High CHchinamilitaryprocurement
threat-intel OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol OpenAI has developed GPT-Red, an automated red-teaming model, to proactively identify and mitigate prompt injection vulnerabilities in its large language models, particularly GPT-5.6 Sol. This model, trained through self… The Hacker News · Jul 16, 2026 High prompt injectionred teamingai security
threat-intel Old UEFI Shims Expose Systems to Secure Boot Bypass A vulnerability in older Microsoft-signed UEFI shim bootloaders has been discovered, allowing attackers to bypass Secure Boot protections and potentially deploy bootkits on UEFI-based systems. These shims, some dating ba… SecurityWeek · Jul 16, 2026 High CVE-2026-8863CVE-2026-10797uefisecure bootvulnerability
vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
threat-intel Police Disrupt a €140M Cyber Fraud Ring in Spain Spanish police disrupted a €140 million cyber fraud ring operating across multiple countries, involving over 70 individuals and a complex network of money laundering. The operation involved sophisticated techniques like… Dark Reading · Jul 16, 2026 High SPPOPAcybercrimefraudmoney laundering
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
threat-intel ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th) The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are imper… SANS Internet Storm Center · Jul 16, 2026 Medium becphishinglinkedin
vulnerability Vulnérabilité dans les produits ESET (16 juillet 2026) A denial-of-service vulnerability has been identified in ESET’s endpoint and server security products. Specifically, versions 12.0.x through 12.0.14.0, 12.1.x through 12.1.2.0, 12.2.x through 12.2.9.0, 13.0.x through 13.… CERT-FR · Jul 16, 2026 Medium CVE-2026-6424denial-of-servicevulnerabilityeset
vulnerability Vulnérabilité dans Traefik (16 juillet 2026) A security vulnerability has been identified in Traefik versions 3.7.x, allowing attackers to bypass security policies. Users are advised to apply the latest security patch released by Traefik to mitigate this risk. CERT-FR · Jul 16, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Drupal (16 juillet 2026) Multiple vulnerabilities have been discovered in Drupal, allowing attackers to compromise data confidentiality and inject malicious code remotely. These vulnerabilities affect older versions of the CMS, requiring immedia… CERT-FR · Jul 16, 2026 Medium CVE-2026-15916CVE-2026-15917CVE-2026-55805drupalvulnerabilitycve
vulnerability Vulnérabilité dans Ruby on Rails (16 juillet 2026) A vulnerability in Ruby on Rails versions prior to 1.7.1 allows for remote code injection via XSS. This means attackers could potentially execute malicious code on vulnerable systems, requiring immediate patching to prev… CERT-FR · Jul 16, 2026 Medium rubyrailsxss