Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 17:49 21/07/2026 UTC
Last updated: 09:08 21/07/2026 UTC

Latest updates

Browse →

Fairlife hit by ransomware attack

Incident

Updated: 17.07.2026 00:09 · First: 17.07.2026 00:09 · 📰 1 src / 2 articles · H score: 25

Fairlife, the Coca-Cola dairy subsidiary, is dealing with a ransomware incident that disrupted U.S. production after the company detected unauthorized access to production-related systems on July 16 and activated incident response and business continuity plans. The company said product quality and safety were not affected and that Canadian production continued normally. On July 21, the Anubis ransomware gang added Fairlife to its leak site, claimed responsibility, alleged it stole approximately 1 TB of data, and said it had encrypted Nutanix systems. Those claims have not been independently verified.

WordPress core pre-auth RCE flaw

Vulnerability

Updated: 18.07.2026 00:20 · First: 18.07.2026 00:20 · 📰 3 src / 5 articles · H score: 80

WordPress core's wp2shell chain combines CVE-2026-63030 and CVE-2026-60137 into unauthenticated remote code execution on vulnerable WordPress 6.9.x and 7.0.x installs. SearchLight Cyber said the exploit chain can be built with GPT5.6 Sol Ultra and starts with REST API batch route confusion and SQL injection before escalating to cache poisoning, authentication bypass, and backdoor plugin upload. Public proof-of-concept exploits are now on GitHub, and watchTowr says it is seeing in-the-wild exploitation after those releases. WordPress fixed the flaws in 6.9.5 and 7.0.2 and enabled forced automatic security updates for affected supported installations.

WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)

Security Patch Release

Updated: 18.07.2026 00:20 · First: 18.07.2026 00:20 · 📰 3 src / 3 articles · H score: 66

WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installations. The vulnerability can be triggered by an anonymous request on a default install with no plugins, covering 6.9.0-6.9.4 and 7.0.0-7.0.1. Researchers later linked the broader wp2shell chain to CVE-2026-63030 and CVE-2026-60137, and confirmed active exploitation against WordPress Core after the fix. Observed abuse included probing, SQL injection attempts, malicious plugin uploads, and PHP webshell deployment on affected servers.

Kiro prompt-injection config rewrite RCE remote code execution flaw

Vulnerability

Updated: 21.07.2026 19:06 · First: 21.07.2026 19:06 · 📰 1 src / 1 articles · H score: 31

AWS Kiro had a prompt-injection RCE vulnerability that let hidden web text rewrite ~/.kiro/settings/mcp.json and launch attacker-controlled code on a developer machine. The flaw bypassed Kiro's approval boundary, turning an ordinary URL-fetch or page-summary action into remote code execution with developer privileges. AWS has patched the issue, and the public research included a working proof of concept.

Google DeepMind launches Gemini 3.5 Flash Cyber via CodeMender for vulnerability discovery and patching

Security Tool/Service

Updated: 21.07.2026 18:09 · First: 21.07.2026 18:09 · 📰 1 src / 1 articles · H score: 26

Google DeepMind released Gemini 3.5 Flash Cyber, a security-focused model built to discover, validate, and patch vulnerabilities faster. The capability is being delivered through CodeMender in a limited-access pilot for governments and trusted partners, narrowing use to frontline defenders. DeepMind positioned the model as a cost-efficient alternative that can be called repeatedly at high speed to scan more code paths. Evaluations showed strong results on Google Chrome, Apple Safari, and the V8 JavaScript Engine, including 55 unique confirmed issues and a 100% reliable remote-code execution exploit that bypassed ASLR and W^X.

Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)

Vulnerability

Updated: 21.07.2026 17:57 · First: 21.07.2026 17:57 · 📰 1 src / 1 articles · H score: 46

CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enables attackers to steal machine keys for persistence.

Qilin (aka Agenda) ransomware deployment after PAN-OS exploitation

Malware Activity

Updated: 21.07.2026 17:04 · First: 21.07.2026 17:04 · 📰 1 src / 1 articles · H score: 40

Qilin (aka Agenda) ransomware was deployed across multiple June 2026 intrusions after attackers exploited CVE-2026-0257 in Palo Alto Networks PAN-OS to gain initial access. The activity expanded from VPN session abuse into credential harvesting, lateral movement, and ransomware encryption on victim environments. Some intrusions stopped at encryption-only operations, while others added double-extortion and data theft, increasing pressure on affected networks. The consistent tooling and staging patterns indicate a repeatable Qilin RaaS operation rather than isolated malware use.

Trim ecosystem shift changes threat-actor operations

Threat Actor Meta

Updated: 21.07.2026 17:00 · First: 21.07.2026 17:00 · 📰 1 src / 1 articles · H score: 22

Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. The platform bundled Claude Opus 4.8, GLM-5, and conventional scanners to automate vulnerability testing and report generation for paying users. The move shows how model-bypass methods can be repackaged into a repeatable criminal service with broader underground reach.

Zimbra SNMP monitoring component command injection

Security Patch Release

Updated: 21.07.2026 16:18 · First: 21.07.2026 16:18 · 📰 1 src / 1 articles · H score: 31

Zimbra 10.1.20 patches a command injection flaw in the SNMP monitoring component that could permit command execution when SNMP notifications are enabled. The fix is part of a broader release that addresses nine security vulnerabilities across the product. Zimbra said the identified issues were not flagged as actively exploited.

Zimbra security patch release for CVE-2026-50055

Security Patch Release

Updated: 21.07.2026 16:18 · First: 21.07.2026 16:18 · 📰 1 src / 1 articles · H score: 14

Zimbra 10.1.20 fixes CVE-2026-50055, a mail forwarding restriction bypass affecting Zimbra accounts with forwarding restrictions. The patch closes a flaw that could let authenticated users exfiltrate email even when forwarding controls are enabled. Zimbra said the issue was not flagged as actively exploited.

Ransomware ecosystem fragments as new groups emerge weekly

Threat Actor Meta

Updated: 21.07.2026 16:00 · First: 21.07.2026 16:00 · 📰 1 src / 1 articles · H score: 47

Ransomware operations are fragmenting and expanding, with more than one new group per week entering the market and increasing extortion volatility. As of June 2026, the ecosystem had 146 active groups and 61 new groups in 2026, leaving defenders to track a faster-moving and more crowded threat landscape. The shift also shows that a small number of brands still drive a large share of public victim claims even as the field churns.

Ransomware victim concentration remained dominated by the top five operations

Trend

Updated: 21.07.2026 16:00 · First: 21.07.2026 16:00 · 📰 1 src / 1 articles · H score: 44

Ransomware victimization remained concentrated across March 2025 to March 2026, with 7,551 public disclosed victims and the top five operations responsible for 44% of them. A small set of groups continued to account for a disproportionate share of extortion harm against organizations. The pattern shows that ransomware impact was still being driven by a few high-volume operators even as the wider ecosystem kept changing.

Empirical Series A cybersecurity funding round

Industry Action

Updated: 21.07.2026 15:47 · First: 21.07.2026 15:47 · 📰 1 src / 1 articles · H score: 14

Empirical raised $25 million in a Series A round, adding fresh capital to expand its cybersecurity products for the agentic AI era. The funding increases the company's total capital raised to $37 million. Brightmind Partners led the round, with Costanoa Ventures and Hyde Park Angels (HPA) also participating. The money is earmarked to accelerate development of Foundation and Radiant, tools aimed at predicting and identifying threats.

Technical analysis of attack chains against Android mobile agent frameworks

Technical Analysis

Updated: 21.07.2026 14:58 · First: 21.07.2026 14:58 · 📰 1 src / 1 articles · H score: 22

Researchers showed that five open-source mobile agent frameworks can be chained into prompt injection, screenshot tampering, UI spoofing, and host command injection, exposing a practical path from on-device deception to PC code execution. The findings affect AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA and are especially relevant because several attacks succeeded in repeated lab trials. The work also identifies concrete defensive gaps in screenshot handling, shell invocation, and broadcast-based input paths. The result is a reusable technical map of how Android agent tooling can be subverted through weak trust boundaries.

Bit2Watt GPU power modulation research on grid destabilization

Technical Analysis

Updated: 21.07.2026 14:24 · First: 21.07.2026 14:24 · 📰 1 src / 1 articles · H score: 22

Researchers published Bit2Watt, showing that ordinary cloud GPU workloads can be shaped into kilohertz-range power oscillations that may destabilize grid behavior in simulation.

Estée Lauder Oracle E-Business Suite personal information leak

Data Leak

Updated: 21.07.2026 01:39 · First: 21.07.2026 01:39 · 📰 2 src / 2 articles · H score: 72

A data leak exposed sensitive personal records tied to Estée Lauder after unauthorized access to its Oracle E-Business Suite used for HR management. The company says the access occurred on or around August 9, 2025, and its investigation determined in June 2026 that an unauthorized third party obtained personal information of certain individuals. The compromised data includes names, addresses, email addresses, dates of birth, SSNs, passport numbers, bank account numbers, health information, and employment information. Estée Lauder is offering 24 months of identity monitoring through Kroll and warning recipients to watch for fraud and suspicious contact.

U.S. Justice Department Operation Offsides domain seizures

Law Enforcement

Updated: 21.07.2026 14:07 · First: 21.07.2026 14:07 · 📰 1 src / 1 articles · H score: 43

The U.S. Justice Department seized and blocked more than 1,000 websites and 1,970 domains tied to unauthorized FIFA World Cup 2026 streaming, disrupting a large illegal-streaming infrastructure. The action was carried out through Operation Offsides with support from the IPR Center and HSI Washington across 54 countries. Officials said the sites also increased consumer risk by exposing viewers to malicious software, malware attacks, and unsecure connections that could compromise personal and financial data.

Craneware data exfiltration and record exposure

Data Leak

Updated: 21.07.2026 12:38 · First: 21.07.2026 12:38 · 📰 1 src / 1 articles · H score: 28

Craneware confirmed a data leak that exposed a significant volume of file names and some employee, customer, and partner records, creating exposure risk across its healthcare software business. The company said the attackers viewed and exfiltrated data from its environment. It also said much of the file-name material was non-sensitive or already public regulatory data, but the theft still widened the exposure. Craneware reported no disruption to customer services and is working to identify affected parties.

Craneware hit by network compromise

Incident

Updated: 21.07.2026 12:38 · First: 21.07.2026 12:38 · 📰 1 src / 1 articles · H score: 16

Craneware disclosed a cybersecurity incident involving unauthorized access to its data environment, putting stored records at risk. The company said a significant volume of file names was viewed and exfiltrated, along with some employee data and a subset of customer and partner records. No customer service disruption was reported, and the company is notifying affected parties.

Famous Chollima ClickFake Interview recruitment scam campaign

Campaign

Updated: 21.07.2026 12:30 · First: 21.07.2026 12:30 · 📰 1 src / 1 articles · H score: 34

A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote access trojans. The operation uses ClickFix-style lures to trick candidates into running terminal commands, turning the interview flow into a malware delivery chain. The approach raises immediate risk to personal devices, saved credentials, and digital assets handled by the targets.

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity

Updated: 21.07.2026 12:30 · First: 21.07.2026 12:30 · 📰 1 src / 1 articles · H score: 29

The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 and cryptocurrency professionals at risk of credential theft and remote compromise. The payloads also bundle credential-harvesting helpers and extension-stealing modules aimed at browser wallets and password managers.

Microsoft WSUS sync timeout manual mitigation

Advisory/Mitigation

Updated: 21.07.2026 12:05 · First: 21.07.2026 12:05 · 📰 1 src / 1 articles · H score: 25

Microsoft issued a manual mitigation for WSUS servers that are hitting sync timeouts and failing to return to normal update deployment. The guidance is aimed at administrators running affected Windows Server Update Services deployments so they can restore Windows Update scans and synchronization. Microsoft also said a service-side mitigation already restored normal behavior for newly installed or rebuilt WSUS servers.

Windows User Profile Service zero-day privilege-escalation flaw (LegacyHive)

Vulnerability

Updated: 17.07.2026 14:05 · First: 17.07.2026 14:05 · 📰 1 src / 2 articles · H score: 41

A public LegacyHive zero-day against Windows User Profile Service can escalate privileges on up-to-date Windows systems, creating admin-level compromise risk. The exploit appeared hours after Microsoft's July 2026 Patch Tuesday and has no CVE ID yet. Testing showed the flaw can let non-admin users alter the classes registry hive and trigger automatic code execution when an administrator logs in. The PoC was later modified to require extra credentials, but it still gives attackers a usable starting point for weaponization.

ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)

Vulnerability

Updated: 20.07.2026 12:29 · First: 20.07.2026 12:29 · 📰 2 src / 2 articles · H score: 43

CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is a pre-auth sandbox-escape RCE that lets attackers reach code execution after breaking out of the platform sandbox. ServiceNow issued July 13th patches for hosted and self-hosted instances, but researchers observed the first attack attempts on Friday and confirmed abuse over the weekend.

Ostium trading platform hit by cyberattack

Incident

Updated: 21.07.2026 01:22 · First: 21.07.2026 01:22 · 📰 1 src / 1 articles · H score: 45

The Ostium trading platform disclosed a $23.75 million theft from its liquidity provider vault after attackers compromised off-chain price feeds, creating fraudulent profits and forcing a trading pause. The exploit used illegitimate price reports and rapid position cycling rather than direct theft of trader collateral. Ostium said existing positions remain open and separate trader collateral was not affected. The platform said it is tracking the stolen funds and working to secure the affected infrastructure.

Reproduced cross-vendor sandbox escapes in AI coding agents

Technical Analysis

Updated: 21.07.2026 00:14 · First: 21.07.2026 00:14 · 📰 1 src / 1 articles · H score: 22

Researchers reproduced sandbox-escape bypasses across Cursor, Codex, Gemini CLI, and Antigravity, showing that agentic coding tools can cross the sandbox boundary through trusted host-side workflows. The finding broadens a reusable configuration-based escape pattern across vendors and weakens isolation assumptions for developer environments. The bypasses rely on prompt injection and workspace-controlled files that external tools later run, load, or scan. Several issues were patched, including CVE-2026-48124 in Cursor 3.0.0 and a Codex CLI allowlist bypass in v0.95.0.

FakeGit GitHub lure campaign

Campaign

Updated: 20.07.2026 21:23 · First: 20.07.2026 21:23 · 📰 1 src / 1 articles · H score: 30

The FakeGit campaign is using nearly 7,600 malicious GitHub repositories to distribute SmartLoader, creating a large-scale lure network that can reach both users and AI agents. More than 800 repositories pose as AI Skills or MCP servers and use convincing setup material to pull victims into the attack chain. The operation's reach and use of trusted developer workflows raise the risk of follow-on payloads such as StealC.

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity

Updated: 20.07.2026 15:30 · First: 20.07.2026 15:30 · 📰 3 src / 3 articles · H score: 15

HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future 2050-05-13 events and moving encrypted stolen files as attachments. Group-IB said the implant uses DNS tunnelling to refresh Entra ID (Azure AD) client credentials, including values written to logAzure.txt and delivered via cloudlanecdn[.]com. The activity was found on at least 12 systems, with three observed actively communicating during June 3, 2026 to July 9, 2026, and the compromised mailbox belonged to an Israeli organization. Group-IB linked the code to Cavern with high confidence, while stopping short of high-confidence attribution to a known threat actor; the targeting and traffic pattern point to a focused espionage operation.

HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities

Campaign

Updated: 20.07.2026 15:30 · First: 20.07.2026 15:30 · 📰 3 src / 3 articles · H score: 22

HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB said the implant hides tasking in 2050-05-13 calendar events, exfiltrates encrypted files as attachments, and also uses DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials from cloudlanecdn[.]com into logAzure.txt. The campaign was observed against Israeli entities, with victim communication seen from June 3, 2026 through July 9, 2026. Group-IB found the implant on at least 12 systems, with three actively communicating during that window, and linked the code to Cavern with high confidence while noting only lower-confidence similarity to Lyceum.

Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users

Campaign

Updated: 20.07.2026 20:29 · First: 20.07.2026 20:29 · 📰 1 src / 1 articles · H score: 25

The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishing and payload-delivery risk. Delivery logs showed 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico accounting for 82.5% of traffic and 96.9% of launch activity. The lure flow used a search-ms: query and a disguised .scr file to open the operator's remote share, while the payload chain installed an infostealer in memory. The exposed toolkit also showed a broader testing pipeline, including alternate signed-binary hijack experiments and other delivery candidates.