[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (5 articles)

|

// AI-powered summary generated at 04:00

> USN-8564-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled certain TLS setup failures, resulting in a NULL pointer dereference. An attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-12184) It was discovered that P...
> How to protect your data after a breakup | Kaspersky official blog
What to do after a breakup so your ex doesn’t retain access to your accounts, subscriptions, and devices.
> Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity.
> OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
> Patch now: WordPress REST API bug allows remote code execution
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code...
> New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
> USN-8560-1: libXfont vulnerabilities
It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56001) It was discove...
> USN-8559-1: rlottie vulnerabilities
It was discovered that rlottie incorrectly handled certain shift operations. An attacker could possibly use this issue to cause rlottie to read out of bounds, resulting in a denial of service or exposing sensitive information. (CVE-2026-10305) It was discovered that rlottie did not properly limit r...
> 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support plat...
> USN-8563-1: nginx vulnerabilities
It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had...
> Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity ad...
> New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed betw...
> Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
> New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
> NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web
F5 a corrigé la CVE-2026-42533, une faille critique de NGINX qui peut faire planter les workers et, parfois, permettre une exécution de code à distance. Le post NGINX – CVE-2026-42533 : cette faille peut faire planter votre serveur Web a été publié sur IT-Connect.
> Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Myt...
> Ernst & Young Data Breach Affects Personal, Financial Information
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
> Infosec News Nuggets — July 20, 2026
Coca-Cola says Fairlife ransomware attack halts US dairy production Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary detected unauthorized access to systems tied to production as part of a ransomware attack, forcing a temporary suspension of Fairlife manufacturing across the U...
> On Flock License Plate Tracking Cameras
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock...
> Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.