Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency,…
Category: securityweek
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.
1.6 Million Likely Impacted by RingCentral Data Breach
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
Over 1,000 Charities Hit by Beacon CRM Data Breach
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
Hackers Exploiting Unpatched GeoServer Zero-Day
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm.
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014.
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system.
Mindgard Raises $30 Million to Protect AI Systems
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.