July 2026

Clover Health Investments Discloses Data Breach

Clover Health Investments Discloses Data Breach 2026-07-21 at 12:36 By Ionut Arghire Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Clover Health Investments Discloses Data Breach Read More »

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Estée Lauder discloses data breach tied to Oracle EBS vulnerability 2026-07-21 at 12:01 By Sinisa Markovic Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its

Estée Lauder discloses data breach tied to Oracle EBS vulnerability Read More »

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner 2026-07-21 at 12:00 By This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner Read More »

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning 2026-07-21 at 11:59 By Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Read More »

UK parliamentary group probes banking barriers for crypto firms

UK parliamentary group probes banking barriers for crypto firms 2026-07-21 at 11:51 By Cointelegraph by Ezra Reguerra A UK parliamentary group launched an inquiry into banking restrictions on crypto firms and consumers, including their impact on investment and competition. This article is an excerpt from Cointelegraph.com News View Original Source

UK parliamentary group probes banking barriers for crypto firms Read More »

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure 2026-07-21 at 11:41 By Eduard Kovacs The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure Read More »

Open-source maintainers still work underfunded as sponsorship crosses $100 million

Open-source maintainers still work underfunded as sponsorship crosses $100 million 2026-07-21 at 11:37 By Anamarija Pogorelec A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend

Open-source maintainers still work underfunded as sponsorship crosses $100 million Read More »

Zimbra Update Patches Critical Vulnerabilities

Zimbra Update Patches Critical Vulnerabilities 2026-07-21 at 11:20 By Ionut Arghire The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Update Patches Critical Vulnerabilities Read More »

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack 2026-07-21 at 10:34 By Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Read More »

Base’s 1:1-backed tokenized equities launch ‘imminent,’ Pollak says

Base’s 1:1-backed tokenized equities launch ‘imminent,’ Pollak says 2026-07-21 at 10:06 By Cointelegraph by Yohan Yun The Coinbase-backed Ethereum layer-2 is preparing to expand its financial offerings as it pivots away from its earlier social-first strategy. This article is an excerpt from Cointelegraph.com News View Original Source

Base’s 1:1-backed tokenized equities launch ‘imminent,’ Pollak says Read More »

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution 2026-07-21 at 09:29 By Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

Nobody was checking the drives that encrypt your laptop

Nobody was checking the drives that encrypt your laptop 2026-07-21 at 08:30 By Anamarija Pogorelec A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG

Nobody was checking the drives that encrypt your laptop Read More »

Cybersecurity jobs available right now: July 21, 2026

Cybersecurity jobs available right now: July 21, 2026 2026-07-21 at 07:00 By Anamarija Pogorelec Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation efforts. You will integrate

Cybersecurity jobs available right now: July 21, 2026 Read More »

AI-generated reports push GNOME to shorten its disclosure window

AI-generated reports push GNOME to shorten its disclosure window 2026-07-21 at 06:53 By Anamarija Pogorelec Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising

AI-generated reports push GNOME to shorten its disclosure window Read More »

Scroll to Top