ICYMI: 2026-07-14
Latest Headlines
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
How Pentera Turns AI Security Workflows into Validation Engines
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
Multiple Jscrambler Packages Impacted by Supply Chain Attack
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
Fortinet Patches Seven Vulnerabilities Across FortiOS, FortiProxy, FortiPAM, and FortiSandbox
Hackers Spoof 3.7 Million OAuth Client IDs to Stealthily Enumerate 2 Million Entra ID Users
Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data
FortiSandbox Vulnerability Allows Attackers to Access VNC Servers of VMs
AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions
Miasma Turns Trusted npm Packages Into Persistent Backdoors for Developer Machines
Maximizing SOC Efficiency: How to Eliminate Alert Overload and Cut MTTR by 21 Minutes Per Case
Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
Spanish Police take down €140 million cyber fraud ring, arrest four
Nearly 300 GitHub repos pose as legit software to push malware
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Windows 11 KB5101650 & KB5099414 cumulative updates released
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
LastPass, Bitwarden users targeted with fake security alerts
You Don’t Have to Run an Exploit to Know If You’re Vulnerable
Microsoft Entra ID gets passkeys default authentication starting September
US sanctions VPN, malware providers for enabling ransomware attacks
– MTZ