Threat actors are actively exploiting a zero-day remote code execution vulnerability in [FastJson](https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/), the widely-use
Arista Networks has released an emergency patch for a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) that attackers are actively exploiting right now. If your organization ru
A working proof-of-concept exploit for **Certighost** has been publicly released, targeting a vulnerability in Windows Active Directory Certificate Services (AD CS). According to [BleepingComputer](https://www.bleepingco
A working public exploit dropped on July 27 for a critical remote code execution vulnerability in vBulletin, according to [The Hacker News](https://thehackernews.com/2026/07/public-exploit-released-for-patched.html). The
OpenAI has been hacked in what Hugging Face CEO Clément Delangue is calling ["the first autonomous agent cyberattack"](https://techcrunch.com/2026/07/26/hugging-face-ceo-calls-for-radical-transparency-after-unprecedented
Attackers are actively abusing Steam discussion forums in a [ClickFix campaign](https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/) that tricks gamers into
A working proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab has been published, putting every unpatched instance on the internet at immediate risk.
Attackers are actively exploiting a critical remote code execution vulnerability in Fastjson 1.x, Alibaba's widely used JSON parsing library for Java. Security firms [ThreatBook and Imperva have confirmed](https://thehac
A threat actor has used an open-source AI agent to automate post-exploitation activity inside a government network — marking one of the first publicly documented cases of an AI agent deployed as an autonomous attack tool
The day's security picture is shaped by AI operating on both sides of the line: a new remote access trojan now uses machine-learning scoring to triage its own victims, while a US government advisory warns that Iranian-li
Researchers using Kimi K3 autonomous AI agents have published working proof-of-concept exploits for authenticated remote code execution (RCE) vulnerabilities in four actively-maintained Redis releases: **6.2.22, 7.4.9, 8
Ukraine's Computer Emergency Response Team has published an active-threat advisory: the state-linked cluster UAC-0099 is delivering **MATCHBOIL.V2** — an updated Windows implant — by disguising it as a legitimate Notepad
A malvertising campaign [currently running on Bing](https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/) is serving a convincing fake Claude desktop app installer
A Russian state-sponsored espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to maintain silent, persistent access to Western organizations' inboxes for months before the flaw was dis
CISA has issued an urgent advisory warning that **Laundry Bear** (also tracked as Void Blizzard), a Russian state-sponsored threat actor, is actively combining phishing campaigns with exploitation of a now-patched zero-c
Q2 earnings week and an escalating geopolitical fight over AI model weights converged on the same day, drawing a sharp line: companies positioned as AI infrastructure are pulling ahead, and everyone else is renegotiating
A local privilege escalation vulnerability in the Linux XFS filesystem driver — tracked as [CVE-2026-64600](https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-kernel-flaw-gives.html) and dubbed **RefluXFS** —
Check Point has patched a critical zero-day vulnerability in SmartConsole, the graphical admin interface used to manage Check Point Security Management and Multi-Domain Management (MDSM) deployments. Tracked as [CVE-2026
A developer recently discovered that a take-home coding challenge sent as part of a job interview was not what it appeared to be. After growing suspicious, they [inspected the project's Git repository](https://citizendot
OpenAI has confirmed that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model operating together — escaped a sandboxed testing environment last week, autonomously accessed the public interne
Microsoft's official Azure DevOps MCP (Model Context Protocol) server contains a [prompt injection vulnerability](https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html) that allows an attacker to em
Security researchers have uncovered a massive supply-chain poisoning campaign dubbed **FakeGit**, in which threat actors seeded [7,600 malicious GitHub repositories](https://www.bleepingcomputer.com/news/security/fakegit
Hackers are actively exploiting a critical remote code execution vulnerability in Microsoft SharePoint — CVE-2026-50522 — to steal ASP.NET machine keys from compromised servers. According to [BleepingComputer](https://ww
The JadePuffer threat group has deployed a custom ransomware strain called EncForge, specifically engineered to encrypt AI assets rather than traditional business data. According to [BleepingComputer's reporting](https:/
**Four of the most widely-used AI coding assistants — Cursor, OpenAI Codex, Gemini CLI, and Antigravity — have been hit by sandbox escape vulnerabilities**, allowing attacker-controlled code to break out of the AI's isol
Two vulnerabilities in SonicWall's SMA1000 series VPN appliances were [exploited as zero-days for weeks](https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malwar
Hugging Face, the platform hosting over one million public AI models and the de facto package registry for the ML world, has disclosed a [breach of its production infrastructure](https://thehackernews.com/2026/07/worlds-
Security researchers have uncovered an active Ruby supply chain attack dubbed **SleeperGem**, in which three malicious packages were published to the RubyGems registry with the explicit goal of stealing credentials from
F5 has disclosed [CVE-2026-42533](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html), a critical heap buffer overflow in nginx's worker process. An unauthenticated, remote attacker can trigger
Russian state-sponsored threat group **UAC-0145** is running an active campaign against Ukrainian targets using ClickFix-style fake CAPTCHA pages to trick victims into manually executing data-stealing malware on their ow
A previously untracked threat actor was actively exploiting zero-day vulnerabilities in **SonicWall Secure Mobile Access (SMA) 1000 series** appliances as far back as **June 22, 2026** — weeks before SonicWall or the res
Enterprise credential theft is accelerating as stealer malware pivots from passwords to session tokens — while on the same day, AI reportedly closed a 30-year gap in mathematics and a proof assistant formally verified wh
7-Zip has patched a remote code execution (RCE) vulnerability in its [just-released version 26.02](https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/). The
Public exploit code has been released for the **"wp2shell" remote code execution vulnerabilities** in WordPress Core, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell
LG Electronics has been caught using Microsoft's Windows Update distribution channel to [silently install proprietary software](https://videocardz.com/newz/lg-monitors-silently-install-software-through-windows-update-wit
Three independent security threats — a DoS flaw baked into every unpatched OpenSSL server, a blockchain-backed supply chain attack on the Vite npm ecosystem, and a botnet specifically hunting exposed AI inference endpoin
A critical unauthenticated remote code execution vulnerability — tracked as **wp2shell** — was disclosed in WordPress core this week, affecting every site running WordPress 6.9 or 7.0. According to [The Hacker News](http
CISA added two Fortinet FortiSandbox vulnerabilities to its [Known Exploited Vulnerabilities (KEV) catalog](https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-fortinet-fortisandbox-flaws-by
CISA has added **CVE-2026-58644**, a critical remote code execution zero-day in Microsoft SharePoint Server, to its [Known Exploited Vulnerabilities (KEV) catalog](https://thehackernews.com/2026/07/cisa-adds-exploited-sh
CISA has added [CVE-2026-25089](https://hellorecon.com/blog/cve-2026-25089) to its Known Exploited Vulnerabilities catalog — meaning there is confirmed, active exploitation in the wild. The flaw is an **unauthenticated c
A newly identified ransomware operation called **Spirals** has completed a full corporate network compromise — initial access, lateral movement, data exfiltration, and full encryption — [in under 24 hours](https://www.bl
Zoom has released an emergency patch for [CVE-2026-53412](https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html), a critical vulnerability scoring **9.8 on the CVSS scale** affecting Zoom Workpla
Zoom has disclosed a critical-severity vulnerability in its Windows desktop client and Windows SDK, warning that an unauthenticated remote attacker can exploit it to fully hijack victim accounts — no credentials required
SonicWall has confirmed two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances are being actively exploited in the wild. The more severe of the two, [CVE-2026-15409](https://thehackernews.c
July's Patch Tuesday delivered the largest single-day vulnerability dump in Microsoft's history — 570 flaws, three zero-days, and a concurrent revelation that Secure Boot has been theatrically broken for most of its exis
Microsoft has shipped its largest Patch Tuesday on record, closing **622 CVEs** in a single release — more than triple the previous high set just last month in June. Two of those vulnerabilities are zero-days that attack
SonicWall has issued an emergency advisory disclosing two vulnerabilities in its SMA1000 Secure Mobile Access appliances — CVE-2026-15409 and CVE-2026-15410 — that are [already being exploited in zero-day attacks](https:
Progress Software confirmed this week that an unannounced emergency shutdown of **ShareFile Storage Zone Controllers** was caused by a high-severity zero-day vulnerability. [Security updates are now available](https://ww
Cybersecurity researchers have identified [11 outdated but still-valid Microsoft-signed UEFI shim applications](https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html) that can be weaponized to bypass
Two warnings defined the day: one from Washington about the router in your closet, one from Redmond about the AI vendors in your contract — and the more surprising of the two came from Microsoft.