vulnerability Multiples vulnérabilités dans les produits Splunk (16 juillet 2026) Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten… CERT-FR · Jul 16, 2026 High CVE-2025-30204CVE-2025-47913CVE-2025-61726vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits F5 (16 juillet 2026) Multiple vulnerabilities have been discovered in F5 products, including BIG-IP, WAF, and NGINX. These vulnerabilities could allow an attacker to achieve remote code execution, denial of service, and data confidentiality… CERT-FR · Jul 16, 2026 High CVE-2026-42533CVE-2026-46333CVE-2026-52865securityvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Cisco RoomOS (16 juillet 2026) Multiple vulnerabilities have been discovered in Cisco RoomOS, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the operating… CERT-FR · Jul 16, 2026 Medium CVE-2026-20150CVE-2026-20153CVE-2026-20156ciscoroomosvulnerability
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
supply-chain Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies A cyberattack on Japan's largest cold-chain logistics company, Nichirei Logistics Group, has severely disrupted the country's food supply chain, impacting KFC restaurants, supermarkets, and various food manufacturers. Th… The Record · Jul 15, 2026 High JPcyberattacksupply chainjapan
threat-intel Forgotten Bootloaders Expose Secure Boot Blind Spot Researchers discovered 11 vulnerable, but still trusted, UEFI shim bootloaders that could have been used to bypass Secure Boot on systems relying on Microsoft's third-party UEFI signing certificate. Despite being outdate… Dark Reading · Jul 15, 2026 High secure bootfirmwareuefi
threat-intel Identity Attacks Overtake Exploits as Top Ransomware Cause Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. Despite widespread deployment of MFA (97… Dark Reading · Jul 15, 2026 High ransomwarephishingmfa
threat-intel Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities The Trump administration has launched Gold Eagle, a new AI-powered cybersecurity clearinghouse to rapidly identify, prioritize, and patch vulnerabilities across industry and critical infrastructure. This initiative, driv… The Record · Jul 15, 2026 Medium vulnerabilitiesaicybersecurity
threat-intel TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Researchers at Palo Alto Networks Unit 42 have uncovered TuxBot v3 Evolution, a developing IoT botnet framework leveraging AI assistance. While the LLM provided some code, it also introduced errors that needed manual cor… The Hacker News · Jul 15, 2026 High iotbotnetddos
threat-intel Guten Tag, Bonjour, Hola to Our European Cyber Defenders! Dark Reading is launching a new section, DR Global Europe, to provide region-specific cybersecurity intelligence tailored for professionals in the EU and UK. This expansion addresses unique cyber threats facing Europe, i… Dark Reading · Jul 15, 2026 High RUUKSPcybersecurityddosransomware
threat-intel Trump’s DNI pick grilled about election security, voter fraud This article focuses on the confirmation hearing for Donald Trump’s nominee to be Director of National Intelligence, Jay Clayton. During the hearing, Clayton was pressed on his views regarding the 2020 election and past… The Record · Jul 15, 2026 Medium USfisaelectionnational security
data-breach 23andMe reaches $18 million settlement with states for massive breach 23andMe has reached a $18 million settlement with 42 state attorneys general due to a significant data breach in 2023 that exposed the genetic and personal information of 6.9 million customers. The company initially deni… The Record · Jul 15, 2026 High data breachgenetic datacybersecurity
threat-intel Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife The UK is intensifying its push for tech sovereignty, driven by concerns over reliance on US tech companies, particularly in the rapidly developing field of AI. Recent restrictions on AI models from Anthropic and OpenAI… Dark Reading · Jul 15, 2026 High UKUSCHtech-sovereigntyaicybersecurity
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel Claude Flaw Automatically Sends Malicious Prompts to AI Agents A vulnerability, dubbed ‘PromptFiction,’ has been discovered in Anthropic’s Claude Desktop application, allowing attackers to automatically submit malicious prompts to the AI assistant with a single click, bypassing the… Dark Reading · Jul 15, 2026 High prompt-injectionai-securityuri-scheme
vulnerability Unpatched Cursor Vulnerability Exposes Users to Code Execution A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor… SecurityWeek · Jul 15, 2026 Critical cursorgitcode execution
threat-intel Dutch police dismantle global crypto investment scam, arrest alleged mastermind Dutch police have dismantled a global cryptocurrency investment scam involving over 700 employees operating from dozens of call centers across multiple countries. The operation, led by a ‘well-known hacker’ with Israeli… The Record · Jul 15, 2026 High NEPOBEcryptocurrencyfraudscam
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch
threat-intel Windows Bind Link Attacks Can Hide Malware From EDR Tools Researchers at Bitdefender have demonstrated three techniques leveraging Windows’ bind links to evade Endpoint Detection and Response (EDR) tools. These techniques – file-binding, process-binding, and silo-binding – allo… SecurityWeek · Jul 15, 2026 High bind linksedr evasionwindows security