2026-07-30 10:35 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Criti…
P50
2026-07-30 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.
P0
2026-07-30 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Amy Ciminnisi · indexed 2026-08-15 14:33 UTC
Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence.
P0
2026-07-30 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC
The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
P0
2026-07-29 21:00 UTC
Vendor Research
AWS Security Blog · CJ Moses · indexed 2026-08-15 18:55 UTC
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the […]
P0
2026-07-29 16:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity ser…
P50
2026-07-29 16:00 UTC
Vendor Research
Google Security Blog · Alex Kilian · indexed 2026-08-15 18:55 UTC
Since its launch in 2016, OSS-Fuzz has contributed significantly to making open-source secure by finding and reporting tens of thousands of bugs. But finding more vulner…
P0
2026-07-29 16:00 UTC
Vendor Research
Microsoft Security Blog · Aarti Borkar · indexed 2026-08-15 18:55 UTC
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog.
P0
2026-07-29 14:53 UTC
Vendor Research
AWS Security Blog · Norbert Manthey · indexed 2026-08-15 18:55 UTC
If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s […]
P0
2026-07-29 13:00 UTC
Vendor Research
Rapid7 · Joel Alcon · indexed 2026-08-15 18:55 UTC
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Man…
P45
2026-07-29 06:40 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-15 18:55 UTC
Link Library - Reflected Cross-Site Scripting The WordPress Plugin Link Library version below 7.9.4 is affected by an unauthenticated Reflected XSS.The 'thumbs_rating_add_vote' AJAX handler reads the 'likelabel' parameter without any sanitization and echoes it back into an HTML response. Joshua Martinelle Wed, 07/29/2026 - 02:40
P0
2026-07-28 23:19 UTC
Vendor Research
Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC
A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an activ…
P45
2026-07-28 18:55 UTC
Vendor Research
AWS Security Blog · Derek Tumulak · indexed 2026-08-15 18:55 UTC
Choosing the right cryptographic key management service on Amazon Web Services (AWS) starts with understanding the difference between AWS Key Management Service (AWS KMS) and AWS CloudHSM. Both provide key storage backed by a hardware security module (HSM) but serve very different needs. AWS KMS is a fully managed service that integrates with all AWS […]
P0
2026-07-28 18:32 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires netwo…
P60
2026-07-28 13:00 UTC
Vendor Research
Rapid7 · Michael Chroney · indexed 2026-08-15 18:55 UTC
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down.Most of that pressure does not come from the frameworks themselves. It comes from the way compliance is still handled …
P0
2026-07-28 13:00 UTC
Vendor Research
Rapid7 · Mikayla Wyman · indexed 2026-08-15 18:55 UTC
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement conti…
P0
2026-07-28 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Lexi DiScola · indexed 2026-08-15 14:33 UTC
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
P0
2026-07-27 16:00 UTC
Vendor Research
Google Security Blog · Heather Adkins · indexed 2026-08-15 18:55 UTC
An IT security team working
P0
2026-07-24 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking system…
P0
2026-07-23 20:14 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796, an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitra…
P5
2026-07-23 18:39 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris"…
P5
2026-07-23 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Thorsten Rosendahl · indexed 2026-08-15 14:33 UTC
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
P0
2026-07-23 15:39 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 08:30 AM PDT Description: The AWS API MCP Server (awslabs.aws-api-mcp-server) is an open-source MCP server that lets AI assistants execute AWS CLI commands against a user's AWS account. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. We identified CVE-2026-16584. On startup, the server loads the data used to enforce this security …
P5
2026-07-23 14:10 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.
P0
2026-07-23 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-15 14:33 UTC
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
P15
2026-07-23 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Mitch Neff · indexed 2026-08-15 14:33 UTC
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
P0
2026-07-23 07:13 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU…
P45
2026-07-22 01:10 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
P0
2026-07-21 20:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-062-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 13:15 PM PDT Description: s2n-tls is an open source C99 implementation of the TLS/SSL protocol. We have identified two distinct issues: - CVE-2026-16317: Silent Drop of TLS 1.3 Encrypted Records in s2n-tls Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently drop individual application data records with…
P5
2026-07-21 19:45 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-061-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/21/2026 12:45 PM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-15957, where uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allo…
P5