Hugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 16, 2026, noting that…
Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the…
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix…
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as…
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, July 20th, 2026…
WordPress RCE, New Windows 0-day and Coca-Cola’s Fairline ransomed
New Windows zero-day, Coca-Cola’s Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from “Nightmare Eclipse” called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be…
IT Security News Hourly Summary 2026-07-20 03h : 1 posts
1 posts were published in the last hour 0:34 : Paidwork – 23,272,765 breached accounts
Paidwork – 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M…
IT Security News Hourly Summary 2026-07-20 00h : 3 posts
3 posts were published in the last hour 21:58 : IT Security News Weekly Summary 29 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
IT Security News Weekly Summary 29
210 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the…
IT Security News Daily Summary 2026-07-19
21 posts were published in the last hour 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the risk radius 16:34 : Hidden Wi‑Fi Killers: Everyday…
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3…
Connecting AI agents to outside services explodes the risk radius
Connect all the things and watch what happens This article has been indexed from www.theregister.com – Articles Read the original article: Connecting AI agents to outside services explodes the risk radius
Hidden Wi‑Fi Killers: Everyday Things Quietly Ruining Your Home Internet
Many everyday objects can quietly wreck your Wi‑Fi, and understanding them is the first step to a more stable home network. From kitchen gadgets to building materials, the invisible radio waves carrying your data are constantly competing with physical…
Helix Data Extortion Group Targets Microsoft SharePoint Using Vishing and MFA Abuse
Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse…
Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in…
IT Security News Hourly Summary 2026-07-19 18h : 3 posts
3 posts were published in the last hour 15:34 : Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION 15:34 : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106 15:6 : Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI…
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects. This article has…
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity…
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to…
What is EDR (Endpoint Detection and Response)? How it Works in 2026
By HOC Team | Last updated: July 2026 | Read time: ~22 min On 19 July 2024, a single… The post What is EDR (Endpoint Detection and Response)? How it Works in 2026 appeared first on Hackers Online Club. This article…
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep…