threat-intel LAPD sidelines relationship with license-plate reader company Flock Safety The Los Angeles Police Department (LAPD) is pausing its relationship with Flock Safety, an ALPR camera company, due to concerns about data privacy, security, and control. The decision follows an inspector general’s audit… The Record · Jul 15, 2026 Medium alprsurveillanceprivacy
vulnerability 2-Click Cursor Exploit Enables Dev Environment Takeover A vulnerability in Cursor AI, an AI coding tool used by over 50,000 enterprises including 64% of the Fortune 500, allows attackers to install malicious code through a cleverly disguised pull request link. Researchers at… Dark Reading · Jul 15, 2026 High aisecuritypull request
threat-intel Virtual Event Today: Cloud & Data Security Summit This article announces a virtual cybersecurity summit focused on cloud and data security strategies, tools, and best practices for July 15th. The event will feature interactive sessions and demonstrations to help attende… SecurityWeek · Jul 15, 2026 Info cloud securitycybersecurityvirtual event
vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
threat-intel Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on col… CISA Advisories · Jul 15, 2026 Info vulnerabilitycvdsecurity
threat-intel US Charges Russian Individuals and Firms for Running Cybercrime Services The US Justice Department has charged three Russian nationals and two companies – ML.Cloud and Media Land – with operating cybercrime services that facilitated attacks against numerous US entities, resulting in tens of m… SecurityWeek · Jul 15, 2026 High CNNLFIcybercrimehostingservicesrussian
threat-intel SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. Traditional SASE security models are failing due to the shift to modern internet protocols and the rise of AI-powered workflows. Employees are now routinely sharing sensitive data with AI tools, bypassing traditional ne… The Hacker News · Jul 15, 2026 High aillmsaas
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
threat-intel New Webinar: Closing the Approval Gap in AI-Era Ad Tech This article discusses the ‘Approval Gap’ in ad tech, where approved marketing tags can lead to a cascade of third- and fourth-party scripts that security teams haven't vetted. AI is accelerating this issue by increasing… The Hacker News · Jul 15, 2026 Medium ad techprivacycompliance
threat-intel A Video Screen That Is Also a Camera Researchers at ETH Zurich have developed a novel ‘Fourier pixel’ that can both capture and emit light, mimicking a telescreen from Orwell’s *1984*. This technology has significant implications for surveillance and data c… Schneier on Security · Jul 15, 2026 Info surveillancedisplaylight field
vulnerability Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addres… SecurityWeek · Jul 15, 2026 High CVE-2026-6875CVE-2026-14902CVE-2026-14903vulnerabilitypatchremote code execution
vulnerability Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution A vulnerability in Cursor, a Git repository hosting platform for Windows, allows malicious cloned repositories to execute arbitrary code on the user's system. The flaw stems from Cursor's tendency to run a `git.exe` file… The Hacker News · Jul 15, 2026 High CVE-2026-26268CVE-2026-10591CVE-2020-26233gitwindowscode execution
threat-intel White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The White House has launched Gold Eagle, a new initiative designed to streamline vulnerability detection and remediation across government and industry. This program leverages AI, specifically Anthropic's Mythos, to proa… SecurityWeek · Jul 15, 2026 Medium vulnerabilityaicybersecurity
malware TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development A new IoT botnet framework, TuxBot v3 Evolution, has been identified, leveraging LLM assistance during development. Developed by an Iranian-based developer, the framework is modular and includes features like DDoS-for-hi… Palo Alto Unit 42 · Jul 15, 2026 CVE-2022-1388CVE-2022-22965CVE-2020-8515
threat-intel OkoBot: new sophisticated malware framework targets cryptocurrency users OkoBot is a sophisticated and evolving malware framework developed by threat actors since 2025, primarily targeting cryptocurrency users. The framework utilizes a layered approach, starting with a PowerShell downloader (… Securelist · Jul 15, 2026 High ransomwarecryptocurrencybrowser
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
threat-intel Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits Nigeria is experiencing a significant rise in cybercrime losses despite a decrease in reported incidents, driven by increasingly sophisticated schemes and a growing digital economy. The country is actively developing cyb… Dark Reading · Jul 15, 2026 High NGcybercrimecybersecurityfraud
vulnerability Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Google and Mozilla have released security updates for Chrome and Firefox, addressing several critical vulnerabilities. These updates include patches for zero-day exploits and prevent potential attacks. While exploit code… SecurityWeek · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764vulnerabilityzero-daypatch