Uncategorized

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC 2026-07-21 at 17:57 By A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Read More »

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities 2026-07-21 at 17:47 By Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Read More »

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access 2026-07-21 at 17:04 By Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Read More »

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit 2026-07-21 at 16:30 By A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Read More »

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs 2026-07-21 at 14:58 By An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Read More »

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner 2026-07-21 at 12:00 By This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner Read More »

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning 2026-07-21 at 11:59 By Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Read More »

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack 2026-07-21 at 10:34 By Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Read More »

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution 2026-07-21 at 09:29 By Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Read More »

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle 2026-07-21 at 01:54 By Reuters The case is one of dozens brought by copyright owners including authors and news outlets against tech companies over the training of their large language models. This article is an excerpt from Latest Technology News |

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle Read More »

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware 2026-07-20 at 23:20 By Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Read More »

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand 2026-07-20 at 21:02 By Thomas Barrabi The Beijing-based firm said Sunday it had experienced “unprecedented compute challenges” and would temporarily focus on ensuring it could serve its existing paid users. The large-language model was trained on 2.8 trillion parameters, making it

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand Read More »

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign 2026-07-20 at 20:29 By A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico,

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign Read More »

Most American voters have favorable view of AI — despite media focus on controversies: poll

Most American voters have favorable view of AI — despite media focus on controversies: poll 2026-07-20 at 20:04 By Thomas Barrabi In a national poll conducted by HarrisX, 56% of voters said they had a favorable view about AI, while 36% had an unfavorable view. 72% of respondents agreed that AI could help people spend

Most American voters have favorable view of AI — despite media focus on controversies: poll Read More »

Scroll to Top