> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 19/07/2026 14:40] [LANGUAGE: EN]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memory Exhaustion BugDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogErnst & Young (EY) Investigates Data Breach Involving Third-Party Support TicketsA cyberattack hit Nichirei, one of Japan’s largest food companiesNew Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RATU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalogTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and AllClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignZoom Fixes CVE-2026-53412, a Critical Account Takeover BugUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsAsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly DownloadsU.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogSonicWall warns of active exploitation of two SMA 1000 zero-daysPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesAttacker Used AI to Build Custom PowerShell Recon MalwareMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogEU Targets FSB-Linked Hackers in New Sanctions Over Cyber SabotageDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksRyuk Ransomware Member Pleads Guilty Over Attacks on U.S. OrganizationsProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know. International Press – Newsletter Cybercrime Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy   Investigation into Odido hack points to possible involvement of the Dutch   German firm files for insolvency, blames cybercrims who shut down production for 6 weeks Japan’s largest taxi operator shuts systems after cyberattack Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365  Two sentenced for hacking Transport for London in UK’s biggest ever cyber crime case   Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man Malware CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots       AsyncAPI npm organization compromised, 2M weekly downloads affected   TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains   NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era   Hacking Large-scale exploitation campaign targeting website content management systems (CMS)   Analyzing AI-Augmented Network Enumeration   LegacyHive public disclosure  Claude for-Chrome Extension-Bypass Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8n   wp2shell: Pre Authentication RCE in WordPress Core   OpenSSL HollowByte: A DoS Hiding in 11 Bytes   wp2shell: Pre Authentication RCE in WordPress Core   Intelligence and Information Warfare   EU targets Russian intelligence officers accused of running a yearslong cyberspying campaign   NSA revives ‘Tailored Access Operations’ name for elite hacking unit   UK and EU strike Russian cyber networks with new sanctions   Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says   Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries   Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor New North Korean campaign uses fake coding interviews to steal developer credentials Cybersecurity xAI Grok CLI Uploads Full Repos and Secrets, Opt-Out Ignored   Satya Nadella’s ‘Reverse Information Paradox’ post draws reactions from AI leaders BabeLLM: A unified taxonomy for NLP-based LLM cybersecurity applications   Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans  The July 2026 Security Update Review   A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers  AI Data Centers Are Being Built Faster Than They Can Be Secured Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei   Ernst & Young discloses data breach after support system hack   Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
[messages.read_original_source] →