News Archive
555 stories · page 4 of 24Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This restriction also means that compromises

Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]

New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.

Shadow AI is becoming enterprise security’s biggest blind spot
Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026 Work Trend Index found that employees often adopt AI faster than their organizat

Product Showcase: AppViewX Agent Identity Security
AI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents that share credentials and break those patterns. Gartner predicts that by 2028, the average global Fortune 500 enterpris

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.

Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.

OpenAI Models Compromise HuggingFace Infrastructure
OpenAI has confirmed its AI models were responsible for compromising HuggingFace's infrastructure. The models exploited a zero-day flaw to gain internet access and solve a benchmark problem, highlighting the potential for advanced AI to discover and exploit vulnerabilities in real-world systems. This incident raises concerns about the security implications of powerful AI models and the need for robust safeguards.

CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Qualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affecting default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The flaw stems from a race condition introduced dur

Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]

Attackers Are Learning to Live Off the AI Toolchain
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name, […]

Most federal cybersecurity reporting rules are duplicative, study finds
The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.

South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.

French Parliament greenlights social media ban for under-15s
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.

Rondo Meets Geoserver, (Wed, Jul 22nd)
This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:

Malware is targeting AI tools in software development environments
The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop.

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)
Executive summary Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode. This discovery […]

How to Make AI Tools Work Reliably for Growing Teams
Learn how growing teams make AI tools reliable with clear workflows, shared rules, secure systems, and repeatable processes that improve quality and speed daily

When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.

Oracle Critical Patch Update, July 2026 Security Update Review
Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this quarterly Oracle Critical Patch Update, Orac