2026-07-30 01:00 UTC
Security Journalism
TIER 3
Dark Reading · Robert Lemos · indexed 2026-08-16 02:02 UTC
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
P0
2026-07-29 21:00 UTC
Vendor Research
TIER 2
AWS Security Blog · CJ Moses · indexed 2026-08-16 02:02 UTC
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the […]
P0
2026-07-29 16:16 UTC
Vendor Research
TIER 2
Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.In the blog post that JetBrains shared in tandem with CVE publication, they stated that …
P50
2026-07-29 16:00 UTC
Vendor Research
TIER 2
Microsoft Security Blog · Aarti Borkar · indexed 2026-08-16 02:02 UTC
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog.
P0
2026-07-29 16:00 UTC
Vendor Research
TIER 2
Google Security Blog · Alex Kilian · indexed 2026-08-16 02:02 UTC
Since its launch in 2016, OSS-Fuzz has contributed significantly to making open-source secure by finding and reporting tens of thousands of bugs. But finding more vulner…
P0
2026-07-29 14:53 UTC
Vendor Research
TIER 2
AWS Security Blog · Norbert Manthey · indexed 2026-08-16 02:02 UTC
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s […]
P0
2026-07-29 13:00 UTC
Vendor Research
TIER 2
Rapid7 · Joel Alcon · indexed 2026-08-16 02:02 UTC
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The…
P45
2026-07-29 06:40 UTC
Vendor Research
TIER 1
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-16 02:02 UTC
Link Library - Reflected Cross-Site Scripting The WordPress Plugin Link Library version below 7.9.4 is affected by an unauthenticated Reflected XSS.The 'thumbs_rating_add_vote' AJAX handler reads the 'likelabel' parameter without any sanitization and echoes it back into an HTML response. Joshua Martinelle Wed, 07/29/2026 - 02:40
P0
2026-07-29 03:19 UTC
Vendor Research
TIER 2
Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC
A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable's Research Special Operations team is monitoring developments and will update t…
P45
2026-07-28 18:55 UTC
Vendor Research
TIER 2
AWS Security Blog · Derek Tumulak · indexed 2026-08-16 02:02 UTC
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS […]
P0
2026-07-28 18:32 UTC
Vendor Research
TIER 2
Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GU…
P60
2026-07-28 13:00 UTC
Vendor Research
TIER 2
Rapid7 · Michael Chroney · indexed 2026-08-16 02:02 UTC
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down.Most of that pressure does not come from the frameworks themselves. It comes from the way compliance is still handled in many organizations, with security work happening in one set of tools and governance, risk, and co…
P0
2026-07-28 13:00 UTC
Vendor Research
TIER 2
Rapid7 · Mikayla Wyman · indexed 2026-08-16 02:02 UTC
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is acc…
P0
2026-07-28 10:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Lexi DiScola · indexed 2026-08-16 02:02 UTC
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
P0
2026-07-27 16:00 UTC
Vendor Research
TIER 2
Google Security Blog · Heather Adkins · indexed 2026-08-16 02:02 UTC
An IT security team working
P0
2026-07-24 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne…
P0
2026-07-23 18:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Thorsten Rosendahl · indexed 2026-08-16 02:02 UTC
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
P0
2026-07-23 14:10 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
P0
2026-07-23 10:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-16 02:02 UTC
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
P15
2026-07-23 10:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Mitch Neff · indexed 2026-08-16 02:02 UTC
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
P0
2026-07-23 07:13 UTC
Government
TIER 1
CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that…
P45
2026-07-22 01:10 UTC
Independent Research
TIER 2
Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
P0
2026-07-21 21:07 UTC
Vendor Research
TIER 2
Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patchesBackgroundOn July 21, Oracle released its Critical Patch Update (CPU) for July 2026, the third quarterly update of the year. This CPU contains fixes for 1235 un…
P5
2026-07-21 16:01 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on …
P15
2026-07-20 15:47 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the a…
P5
2026-07-20 09:36 UTC
Vendor Research
TIER 2
Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-16 02:02 UTC
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-w…
P70
2026-07-17 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira · indexed 2026-08-16 02:02 UTC
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
P35
2026-07-16 23:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Ria Bhatia · indexed 2026-08-16 02:02 UTC
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.
P0
2026-07-16 18:00 UTC
Vendor Research
TIER 2
Cisco Talos Intelligence Blog · Joe Marshall · indexed 2026-08-16 02:02 UTC
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
P0
2026-07-16 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes…
P10