Hackers Exploiting Palo Altos PAN-OS Vulnerability to Deploy Qilin Ransomware
Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI)
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Swati KhandelwalJul 20, 2026Vulnerability / Endpoint Security Opening a crafted XZ archive in 7-Zip could let an attacker run code
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow
Weekly Cyber Security Newsletter Bulletin EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can