threat-intel Finland issues wanted notice for hacker behind massive psychotherapy data breach Finnish authorities have issued a wanted notice for convicted hacker Aleksanteri Kivimäki, following a Supreme Court ruling, in connection with a massive data breach targeting psychotherapy provider Vastaamo. The breach,… The Record · Jul 14, 2026 High FIdata breachcybercrimehacking
threat-intel Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads A security vulnerability exists in the Claude for Chrome extension, allowing malicious extensions to trigger unauthorized actions within the user's Gmail, Google Docs, and Calendar accounts. The vulnerability stems from… The Hacker News · Jul 14, 2026 High prompt-injectionextensionvulnerability
vulnerability Adobe Patches Critical ColdFusion Vulnerabilities Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuse… SecurityWeek · Jul 14, 2026 High CVE-2026-48318CVE-2026-48322CVE-2026-48284securitypatchvulnerability
threat-intel LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts Blackpoint Cyber researchers identified LabubaRAT, a new Rust-based remote access trojan (RAT) that disguises itself as NVIDIA software to gain access to Windows systems. The RAT is highly configurable, utilizing multipl… The Hacker News · Jul 14, 2026 High rustremote access trojanmalware-as-a-service
threat-intel Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook? Several states – Illinois, New York, and California – are enacting laws to regulate the deployment of increasingly powerful frontier AI models, requiring developers to establish comprehensive AI frameworks addressing ris… Dark Reading · Jul 14, 2026 High aifrontier-airegulation
threat-intel ClickFix's Mushrooming Ecosystem Demands New Defense Tactics ClickFix, initially a social engineering attack vector, has evolved into a sophisticated malware-as-a-service (MaaS) ecosystem, outpacing traditional security defenses. Attackers are now utilizing a range of malware, inc… Dark Reading · Jul 14, 2026 High social engineeringmalware-as-a-serviceyara
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
threat-intel NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says Russian state-backed hackers are systematically compromising internet-connected security cameras across Europe and Ukraine to gather intelligence on NATO military logistics and identify Ukrainian troops for targeting. Th… The Record · Jul 14, 2026 High NEUKCHcyber espionagerussian hackingmilitary intelligence
vulnerability RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Two vulnerabilities in RabbitMQ could allow attackers to steal OAuth secrets, expose tenant data, and potentially take over entire messaging infrastructure. The flaws have been patched, but organizations need to take imm… The Hacker News · Jul 14, 2026 High CVE-2026-57219CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without expli… SecurityWeek · Jul 14, 2026 High browserchromeai
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability ABB Ability Edgenius ABB has released a security update to address a Linux kernel vulnerability (CVE-2026-31431) in its Ability Edgenius edge computing platform. This vulnerability, known as ‘Copy Fail,’ could allow a local attacker to gain… CISA Advisories · Jul 14, 2026 High CVE-2026-31431linuxvulnerabilityedge computing
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
vulnerability ABB T-MAC Plus ABB has identified and addressed several vulnerabilities in its T-MAC Plus Terminal Management System, primarily related to improper configuration and access controls. These vulnerabilities could allow an attacker to exe… CISA Advisories · Jul 14, 2026 High CVE-2025-14771CVE-2025-14772CVE-2025-14773iisxsscwe-552
vulnerability Rockwell Automation 1715-AENTR EtherNet/IP Adapter Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter is vulnerable to a security flaw that could allow unauthorized remote access to a debug port, potentially leading to file deletion, task stopping, memory modification,… CISA Advisories · Jul 14, 2026 High CVE-2026-10577vulnerabilitycveindustrial control systems
threat-intel ABB Advant Master Online Builder ABB has identified and addressed a vulnerability in its Advant Master Online Builder software, where an incorrect version of the Online Builder could lead to unauthorized DLL loading and potential code execution. The vul… CISA Advisories · Jul 14, 2026 High CVE-2025-13162vulnerabilitydll injectionremote code execution
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
threat-intel How Pentera Turns AI Security Workflows into Validation Engines Pentera has introduced a new protocol, MCP, to integrate its security validation platform directly into existing AI security workflows. Traditionally, AI security tools relied on fragmented risk signals, leading to guess… The Hacker News · Jul 14, 2026 High aivalidationattack-path
threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login aler… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id