SharePoint CVE-2026-50522: Critical RCE Under Active Exploitation to Steal Machine Keys
July 22, 2026 Microsoft SharePoint administrators are racing to patch a critical remote code execution vulnerability that attackers are actively exploiting in the wild. The flaw, tracked as CVE-2026-50522, allows unauthenticated remote code execution…
Anubis Ransomware Attack on Coca-Cola and Fairlife
July 21, 2026 The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary. Consequently, the company was forced to suspend production at its U.S. facilities after attackers gained unauthorized access…
ServiceNow CVE: Critical Pre-Auth RCE Exploit
July 21, 2026 A critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform is being actively exploited in the wild. The flaw, tracked as CVE-2026-6875, allows unauthenticated attackers to escape the JavaScript sandbox…
Hugging Face AI Agent Breach
July 20, 2026 Hugging Face, the world’s largest open-source artificial intelligence platform, disclosed that attackers breached its production infrastructure using an autonomous AI agent system. The intrusion marks one of the first confirmed cases…
HelloNet APT Campaign Abuses ViPNet Update System
July 20, 2026 An advanced threat actor is abusing the update mechanism of ViPNet, a Russian-certified private networking suite, to implant persistent backdoors in government agencies and critical infrastructure across Russia. Dubbed HelloNet by Kaspersky…
Abbott Laboratories Double Cyber Incident: ShinyHunters Claims PII Records Stolen in Vishing Attack
July 19, 2026 Abbott Laboratories, one of the world’s largest medical technology companies, is investigating two separate cybersecurity incidents disclosed this week. One involves the ShinyHunters extortion gang, which claims to have stolen more than 30…
wp2shell WordPress Core RCE: CVEs Enable Unauthenticated Code Execution
July 18, 2026 A critical pair of vulnerabilities in WordPress Core, dubbed wp2shell, enables unauthenticated remote code execution on millions of websites. The flaws are tracked as CVE-2026-63030 and CVE-2026-60137. They were patched in WordPress 6.9.5…
OpenSSL HollowByte DoS Flaw: 11-Byte Payload Freezes Server Memory
July 17, 2026 OpenSSL silently patched a denial-of-service vulnerability dubbed HollowByte that lets unauthenticated attackers freeze server memory with an 11-byte payload. There is no CVE assigned, no advisory published, and no changelog entry pointing…
CVE-2026-58644: CISA Adds SharePoint RCE Zero-Day to KEV Catalog
July 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. This critical Microsoft SharePoint Server flaw carries a CVSS score of 9.8 and…
OkoBot Malware Framework Deploys 20+ Payloads to Steal Crypto and Credentials
July 16, 2026 Kaspersky’s Global Research and Analysis Team has uncovered a sophisticated malware framework called OkoBot that delivers over 20 malicious payloads to steal cryptocurrency wallet seed phrases, browser credentials, and sensitive data.…