The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July…
Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
Zimbra fixed a critical Zimbra Collaboration Suite (ZCS) command injection flaw in version 10.1.20 that could allow attackers to abuse the SNMP service and execute arbitrary commands on affected servers. The flaw affects environments where SNMP notifications are enabled, potentially…
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…
IT Security News Hourly Summary 2026-07-22 15h : 14 posts
14 posts were published in the last hour 13:5 : Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks 13:4 : New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies 13:4 : Chick-fil-A loyalty…
Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks
Oracle has released its July 2026 Critical Patch Update (CPU), shipping 1,449 security patches that collectively remediate more than 1,200 vulnerabilities across databases, middleware, cloud services, and enterprise applications, in what is now the largest CPU in the company’s history.…
New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies
NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating proxy infrastructure. The framework came to light when a single Pastebin post was…
Chick-fil-A loyalty accounts hijacked using stolen passwords
If you have a Chick-fil-A One account, now is a good time to change your password—and make sure it’s one you don’t use anywhere else. This article has been indexed from Malwarebytes Read the original article: Chick-fil-A loyalty accounts hijacked…
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Move over Flipper. There’s a new Dophin X in town This article has been indexed from www.theregister.com – Articles Read the original article: Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
StrongestLayer Raises $4.1 Million in Seed Funding Extension
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
Car Alarm Devices Vulnerable to Hacking
Millions of vehicles contain hackable aftermarket alarm systems that dealerships installed without owner knowledge or consent, according to new security research. This article has been indexed from CyberMaterial Read the original article: Car Alarm Devices Vulnerable to Hacking
Paidwork breach exposes 23M users
A data breach at Paidwork has exposed personal information belonging to more than 23 million users of the microtask platform. This article has been indexed from CyberMaterial Read the original article: Paidwork breach exposes 23M users
Glow raises $180M Series A at $1.2B valuation
Glow, a Palo Alto-based cybersecurity startup, emerged from stealth mode on Wednesday as a unicorn after raising $180 million in Series A funding at a $1.2 billion valuation. This article has been indexed from CyberMaterial Read the original article: Glow…
Council worker gets suspended sentence for data snooping
A local government employee in England has been convicted of unlawfully accessing sensitive personal data after snooping on records of people he knew. This article has been indexed from CyberMaterial Read the original article: Council worker gets suspended sentence for…
Google Launches Gemini 3.5 Flash Cyber AI Model
Google has launched Gemini 3.5 Flash Cyber, a specialized AI model built to accelerate vulnerability discovery and remediation in software code. This article has been indexed from CyberMaterial Read the original article: Google Launches Gemini 3.5 Flash Cyber AI Model
4 ways to secure local developer IDEs and tools without sacrificing velocity
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: 4 ways to secure local developer IDEs and tools…
Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
Apple has addressed a year-old vulnerability in its “Hide My Email” privacy feature, which could expose users’ real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple’s privacy claims. Hide My Email,…
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects…
Paidwork breach exposes data of 23 million users: Check if you’re affected
A reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here’s how to check if you’re affected. This article has been indexed from Malwarebytes Read the original article: Paidwork breach exposes data…
Greedy ransomware crews return for seconds after victims cough up first extortion payments
Some never saw their files again either, infosec biz Proofpoint finds This article has been indexed from www.theregister.com – Articles Read the original article: Greedy ransomware crews return for seconds after victims cough up first extortion payments
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers…
Open AI Claims Its AI Models Went Rogue and Hacked Another Company
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves This article has been indexed from www.infosecurity-magazine.com Read the original article: Open AI Claims Its…
New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More…
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below…
First-Person Identity Theft Story
Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of…