ICYMI: 2026-07-21
Latest Headlines
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
Now You Can teach a Skill to Claude by Just Recording your Screen
Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities
This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
Trump’s AI Safety Chief Quits Just Three Months After Taking Charge
Hackers Abuse GitHub Actions to Backdoor AsyncAPI npm Packages With Miasma RAT
APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials
Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
Critical SharePoint RCE flaw exploited to steal machine keys
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
Critical wp2shell WordPress flaws exploited to install webshells
Closing the Identity Gaps in Critical Infrastructure Security
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Microsoft shares manual fix for WSUS sync delays and timeouts
Windows LegacyHive zero-day flaw gets free, unofficial patches
– MTZ