148 posts were published in the last hour
- 20:34 : CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPress
- 20:34 : Top 5 Disaster Recovery Companies in 2026
- 20:34 : AWS Billion-Dollar Software Bug Explained
- 20:34 : Scammers impersonate FBI on social media, prey on crime victims
- 20:4 : FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- 19:34 : Malicious cloud customers can bring down the power grid
- 19:5 : WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
- 19:5 : IT Security News Hourly Summary 2026-07-20 21h : 5 posts
- 19:4 : Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
- 19:4 : Frontier LLMs couldn’t help Hugging Face fight off evil agents
- 19:4 : The Odyssey piracy scams surface hours after its theatrical debut
- 18:5 : The 12 Best Identity Threat Detection & Response (ITDR) Solutions, Compared and Priced (2026)
- 18:5 : Hugging Face Stops AI-Driven Cyberattack
- 18:4 : Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- 17:34 : Hugging Face Discloses Autonomous AI Agent Attack
- 17:34 : EU Mandates Driver Distraction Warning Systems in All New Vehicles Amid Privacy and Safety Debate
- 17:34 : Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents
- 17:34 : Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts
- 17:34 : HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
- 17:27 : Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
- 17:27 : Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
- 17:27 : Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
- 17:27 : Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
- 17:27 : The Odyssey piracy scams appear within hours of the movie’s release
- 17:27 : 2026 ISO and CSA STAR certificates are now available with two additional services
- 16:34 : Security Is a Platform Property, Not a Pipeline Step
- 16:34 : Fix Circular Dependencies in PostgreSQL Row-Level Security With SECURITY DEFINER Functions
- 16:34 : Researchers trace SonicWall SMA1000 exploitation to late June
- 16:5 : IT Security News Hourly Summary 2026-07-20 18h : 17 posts
- 16:5 : Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
- 16:4 : Odyssey piracy scams appear within hours of the movie’s release
- 15:34 : WordPress Remote Code Execution Flaws Get Public Exploits
- 15:34 : Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
- 15:34 : HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
- 15:34 : Hackers steal customer data from major hospital software vendor
- 15:7 : LG Monitors Spotted Installing Adware-Like App on Windows PCs
- 15:7 : The Agent Security Split: Tool Layer vs Sandbox Layer
- 15:7 : Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
- 15:7 : Microsoft Releases KB5121767 Out-of-Band Update to Fix Dell USB-C Compatibility Bug
- 15:6 : Researchers Claim LG Monitors are Silently Installing Adware on Windows Using App
- 15:6 : Microsoft to End OneDrive Sync App Updates for Windows 10
- 15:5 : GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25
- 15:5 : ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands
- 15:5 : Healthcare giant Abbott probes two cyber incidents amid extortion claims
- 15:5 : Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
- 15:5 : Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
- 15:4 : ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
- 15:4 : Paidwork breach exposes sensitive data of 23 million user
- 15:4 : Cruciferra Crypter Uses Process Ghosting to Evade Detection
- 14:34 : Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
- 14:34 : SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
- 14:34 : JadePuffer Returns With Ransomware Designed to Wipe AI Models
- 14:34 : Cyber Briefing: 2026.07.20
- 14:6 : What Does the Cyber Industry Want to See From the New UK Government?
- 14:5 : An ordinary laptop solved a problem thought to require a quantum computer
- 14:5 : Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
- 14:5 : Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud
- 14:5 : ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
- 14:5 : Researchers Build WordPress Exploit Using OpenAI’s GPT
- 13:35 : GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
- 13:35 : TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details
- 13:34 : Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
- 13:34 : Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
- 13:34 : HOLLOWGRAPH malware hides in M365 calendar invites
- 13:34 : Craneware data breach affects 2,000+ US hospitals
- 13:34 : Microsoft releases Dusseldorf OAST platform
- 13:34 : Federal employees can download TikTok on work phones
- 13:34 : Capital One Open Sources AI VulnHunter Tool
- 13:6 : Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
- 13:6 : New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
- 13:5 : Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
- 13:5 : Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
- 13:5 : OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
- 13:5 : IT Security News Hourly Summary 2026-07-20 15h : 4 posts
- 13:4 : Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
- 13:4 : Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
- 12:34 : The Hidden Risk in Enterprise AI Agents: Ungoverned Context
- 12:34 : New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
- 12:4 : New Index Tracks Material Breaches — And Refuses to Add Up the Losses
- 11:37 : FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
- 11:37 : FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
- 11:36 : Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
- 11:35 : On Flock License Plate Tracking Cameras
- 11:35 : Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
- 11:34 : Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
- 11:34 : Ernst & Young Data Breach Affects Personal, Financial Information
- 11:7 : One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
- 11:6 : Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
- 11:6 : Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
- 11:5 : Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability
- 11:5 : Hugging Face breached by autonomous AI agent
- 10:37 : LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
- 10:36 : The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
- 10:36 : CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
- 10:36 : Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
- 10:35 : Watch on Demand: Cloud & Data Security Summit
- 10:8 : Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
- 10:7 : Hugging Face Hacked in Autonomous AI Attack
- 10:6 : Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
- 10:5 : New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
- 10:5 : IT Security News Hourly Summary 2026-07-20 12h : 9 posts
- 10:5 : Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
- 9:48 : Apps Marketed to US Troops Are Shipping Chinese and Russian Code
- 9:46 : AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
- 9:44 : GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
- 9:41 : Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
- 9:38 : The secret problem in AI infrastructure: Why MCP security starts with secrets
- 9:37 : How agentic endpoint security shuts down IDE-based supply chain attacks
- 9:35 : Your attack surface is bigger than you think
- 9:9 : The Windows 10 hangover is becoming a security problem
- 9:6 : FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft
- 8:34 : Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
- 8:34 : Chrome 150 Update Patches Severe Memory Safety Bugs
- 8:11 : North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
- 8:11 : U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
- 7:34 : The Rise of Calendar Phishing
- 7:34 : Google’s Next-Gen Gemini Delayed Over Coding Disappointment
- 7:34 : A week in security (July 13 – July 19)
- 7:34 : Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents
- 7:5 : IT Security News Hourly Summary 2026-07-20 09h : 11 posts
- 7:4 : Global Users Turn To Chinese AI As Costs Soar
- 7:4 : U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
- 6:32 : Start-Ups Shift AI Tasks To Smartphones
- 6:32 : GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
- 6:32 : Weekly Cybersecurity Newsletter – The 50 Biggest Cybersecurity Stories – Microsoft Patch, AI Attack, Exploits Releases, Data Breaches & More
- 6:32 : PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
- 6:32 : Unpatched Backdoor Identified in Firmware of Multiple Wi-Fi Routers
- 6:32 : Meet Dusseldorf, Microsoft’s open-source out-of-band security platform
- 6:5 : TfL Hackers Sentenced To Years In Prison
- 6:5 : Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
- 6:5 : North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
- 6:4 : Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
- 6:4 : More alerts are making your team slower, and an outcome-based SOC fixes that
- 6:4 : SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
- 6:4 : World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
- 5:34 : WP2Shell WordPress Vulnerabilities Exploited in the Wild
- 5:34 : A forensic tool for backdoored code completions in AI assistants
- 5:5 : Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
- 5:4 : Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
- 4:34 : 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
- 4:34 : Nearly half of open-source AI projects never reach production
- 2:6 : ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
- 1:34 : WordPress RCE, New Windows 0-day and Coca-Cola’s Fairline ransomed
- 1:5 : IT Security News Hourly Summary 2026-07-20 03h : 1 posts
- 0:34 : Paidwork – 23,272,765 breached accounts
- 22:5 : IT Security News Hourly Summary 2026-07-20 00h : 3 posts
- 21:58 : IT Security News Weekly Summary 29
- 21:55 : IT Security News Daily Summary 2026-07-19