Data Breaches Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. Ionut ArghireJuly 21, 2026
Vulnerabilities Exploitation of ServiceNow Vulnerability Seen Days After Disclosure The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. Eduard KovacsJuly 21, 2026
Malware & Threats SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. Eduard KovacsJuly 20, 2026
Data Breaches New Index Tracks Material Breaches — And Refuses to Add Up the Losses Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. Eduard KovacsJuly 20, 2026
Data Breaches Ernst & Young Data Breach Affects Personal, Financial Information Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. Ionut ArghireJuly 20, 2026
Vulnerabilities WP2Shell WordPress Vulnerabilities Exploited in the Wild Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. Eduard KovacsJuly 20, 2026
Compliance Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. SecurityWeek NewsJuly 17, 2026
Vulnerabilities Fresh SharePoint Vulnerability Exploited Soon After Disclosure The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. Ionut ArghireJuly 17, 2026
Ransomware Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack The company has yet to determine the full scope, nature, and impact of the incident. Ionut ArghireJuly 17, 2026
Artificial Intelligence AI Data Centers Are Being Built Faster Than They Can Be Secured AI infrastructure introduces new security risks that traditional data center designs were never built to handle. Kevin TownsendJuly 16, 2026
Endpoint Security Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. Eduard KovacsJuly 16, 2026
Artificial Intelligence Unpatched Cursor Vulnerability Exposes Users to Code Execution An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. Ionut ArghireJuly 15, 2026
Endpoint Security Windows Bind Link Attacks Can Hide Malware From EDR Tools Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. Kevin TownsendJuly 15, 2026
Artificial Intelligence White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The new program stems from an AI-focused Executive Order signed by President Trump on June 2. Eduard KovacsJuly 15, 2026
Vulnerabilities SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. Eduard KovacsJuly 15, 2026
Vulnerabilities Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. Ionut ArghireJuly 14, 2026
Cybercrime Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. Eduard KovacsJuly 14, 2026
Artificial Intelligence Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. Eduard KovacsJuly 14, 2026
Compliance Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules A new CMMC review and reform task force will conduct a comprehensive review of the program. Eduard KovacsJuly 14, 2026
Hacker Conversations Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Once a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate. Kevin TownsendJuly 13, 2026