> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 26/07/2026 11:42] [LANGUAGE: EN]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Water and Energy Control SystemsAustralian energy provider Origin Energy disclosed a data breach impacting customer dataGoogle Fined €890M Under EU Digital Markets Act Over Search and Play Store PracticesThailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedUAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian OrganizationsThe AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are HesitatingUS Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogChaos ransomware deploys browser-based msaRAT to evade network detectionGoogle Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingCheck Point patches actively exploited SmartConsole authentication bypass flawCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protectionsAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theftU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogOpenAI AI models exploited zero-days to reach Hugging Face in benchmark testPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Zimbra 10.1.20 patches multiple security issues, including a critical command injection bugQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN AccessAttackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military EspionageCritical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversAI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion CampaignVolexity Uncovers Zero-Day Campaign Targeting SonicWall VPN AppliancesAttackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits International Press – Newsletter Cybercrime Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware   A blow against one of the world’s most dangerous phishing groups   The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results Swiss train maker tells ransomware crooks to get off at the next stop Europol-led action against nihilistic violent extremist network “The Com”   Illinois Man Sentenced to Over Six Years in Prison for Identity Theft and Wire Fraud   Origin Energy investigates alleged cyber attack after hacker claims to have stolen data of two million customers in ransom bid  Malware SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor   HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels   AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware   Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel   Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI   Hacking Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)       World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent 5-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533   Smashing the ServiceNow Sandbox – Pre Authentication RCE   Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC OpenAI and Hugging Face partner to address security incident during model evaluation   The Vulnerability That Turned Adobe’s 300M-Install Extension Into a Full WhatsApp Takeover  CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access American Hackers-for-Hire Proposal Sparks Heavy Criticism   Intelligence and Information Warfare   Brochure Cybersecurity advisory Russian state actors are compromising IP cameras   UAC-0145 Primary Compromise Vectors as of July 2026   Inside Russia’s Camera-Hacking Espionage Campaign  Blog JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake  CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity   UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3 Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged   Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure  Cybersecurity Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Identity Attacks Overtake Exploits as Top Ransomware Cause   LG to Ban Residential Proxies from Smart TV Apps   Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber   Google hit with $1 billion EU fine, in ‘constructive’ talks to avoid more penalties   Is Patching Dead? Vulnerability Management in the Post-Mythos Era How AI guardrails are impeding the work of offensive cybersecurity researchers   Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
[messages.read_original_source] →