SecurityTicks

Paidwork breach exposes sensitive data of 23 million user

Paidwork breach exposes sensitive data of 23 million user 2026-07-20 at 17:52 By Sinisa Markovic Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, […]

Paidwork breach exposes sensitive data of 23 million user Read More »

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 2026-07-20 at 17:33 By A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch 2026-07-20 at 17:11 By Eduard Kovacs The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article is an excerpt

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Read More »

Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

Mythos Didn’t Break Your Security Program. Your Exposure Window Could. 2026-07-20 at 17:06 By The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would

Mythos Didn’t Break Your Security Program. Your Exposure Window Could. Read More »

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More 2026-07-20 at 16:32 By A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks,

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More Read More »

Peter Brandt predicts the exact day Bitcoin’s bear market will be over

Peter Brandt predicts the exact day Bitcoin’s bear market will be over 2026-07-20 at 16:30 By Cointelegraph by Ciaran Lyons Renowned trading analyst Peter Brandt says investing in Bitcoin today, will pay off much better in two to three years than buying AI stocks at current prices. This article is an excerpt from Cointelegraph.com News

Peter Brandt predicts the exact day Bitcoin’s bear market will be over Read More »

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches 2026-07-20 at 16:19 By Sinisa Markovic Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches Read More »

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC 2026-07-20 at 15:35 By Pauline Bolaños Vexed researcher Nightmare-Eclipse (aka Chaotic Eclipse, Dead Eclipse, and MSNightmare) released his ninth unpatched Windows vulnerability called LegacyHive. This latest bug drop is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading

LegacyHive: Nightmare-Eclipse’s Latest Zero-Day Drop with a Stripped PoC Read More »

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability 2026-07-20 at 15:32 By Ionut Arghire Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Read More »

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine 2026-07-20 at 15:13 By At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine Read More »

New Index Tracks Material Breaches — And Refuses to Add Up the Losses

New Index Tracks Material Breaches — And Refuses to Add Up the Losses 2026-07-20 at 14:46 By Eduard Kovacs Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek. This

New Index Tracks Material Breaches — And Refuses to Add Up the Losses Read More »

Ernst & Young Data Breach Affects Personal, Financial Information

Ernst & Young Data Breach Affects Personal, Financial Information 2026-07-20 at 14:27 By Ionut Arghire Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Ernst & Young Data Breach Affects Personal, Financial Information Read More »

Crypto institutions look beyond audits as trust signals falter: Hacken

Crypto institutions look beyond audits as trust signals falter: Hacken 2026-07-20 at 14:00 By Cointelegraph by Ezra Reguerra Institutional due diligence is shifting toward continuous monitoring, signer controls and incident readiness after operational failures accounted for most crypto losses. This article is an excerpt from Cointelegraph.com News View Original Source

Crypto institutions look beyond audits as trust signals falter: Hacken Read More »

Capital B approves 10-for-1 reverse stock split to broaden investor base

Capital B approves 10-for-1 reverse stock split to broaden investor base 2026-07-20 at 13:54 By Cointelegraph by Yohan Yun Europe’s second-biggest Bitcoin treasury company said the September reverse stock split should attract more institutional investors to the French company. This article is an excerpt from Cointelegraph.com News View Original Source

Capital B approves 10-for-1 reverse stock split to broaden investor base Read More »

Hugging Face breached by autonomous AI agent

Hugging Face breached by autonomous AI agent 2026-07-20 at 13:52 By Zeljka Zorz Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16),

Hugging Face breached by autonomous AI agent Read More »

Russia’s parliament to hold final readings on crypto bill Tuesday

Russia’s parliament to hold final readings on crypto bill Tuesday 2026-07-20 at 13:37 By Cointelegraph by Helen Partz Russia’s State Duma is set to consider the crypto regulation bill in second and third readings, with rules for investors and cross-border payments included. This article is an excerpt from Cointelegraph.com News View Original Source

Russia’s parliament to hold final readings on crypto bill Tuesday Read More »

Scroll to Top