OpenSSL HollowByte DoS Flaw: 11-Byte Payload Freezes Server Memory
July 17, 2026 OpenSSL silently patched a denial-of-service vulnerability dubbed HollowByte that lets unauthenticated attackers freeze server memory with an 11-byte payload. There is no CVE assigned, no advisory published, and no changelog entry pointing…
CVE-2026-58644: CISA Adds SharePoint RCE Zero-Day to KEV Catalog
July 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. This critical Microsoft SharePoint Server flaw carries a CVSS score of 9.8 and…
OkoBot Malware Framework Deploys 20+ Payloads to Steal Crypto and Credentials
July 16, 2026 Kaspersky’s Global Research and Analysis Team has uncovered a sophisticated malware framework called OkoBot that delivers over 20 malicious payloads to steal cryptocurrency wallet seed phrases, browser credentials, and sensitive data.…
Zoom CVE: Critical Account Takeover Vulnerability in Windows Desktop Client
July 15, 2026 Zoom has released security updates for a critical vulnerability in its Windows desktop client and SDK that could allow an unauthenticated attacker to hijack accounts over the network. The flaw, tracked as CVE-2026-53412, carries a CVSS…
Microsoft July 2026 Patch Tuesday Fixes Record 622 Flaws: Two Zero-Days Under Active Attack | SharePoint & AD FS
July 15, 2026 Microsoft shipped its largest Patch Tuesday on record today. The July 2026 release patches an unprecedented 622 CVEs across Windows, Office, Edge, SharePoint, Azure, SQL Server, and more. Two of those fixes close zero-day vulnerabilities…
SonicWall SMA1000 Zero-Day Exploitation
July 15, 2026 SonicWall has disclosed two actively exploited zero-day vulnerabilities in SMA1000 secure remote access appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, both flaws carry a combined CVSS 10.0 severity rating. The U.S. Cybersecurity…
Nihon Kotsu Cyberattack Shuts Down Japan Largest Taxi Fleet
July 14, 2026 Japan’s largest taxi operator, Nihon Kotsu, suffered a damaging cyberattack on July 12, 2026, forcing the company to shut down critical systems and suspend dispatch services across multiple cities. The incident highlights the growing…
CISA KEV Alert: Joomla iCagenda and Balbooa Forms Zero-Days Enable Unauthenticated RCE
July 13, 2026 CISA has added two maximum-severity Joomla extension flaws to its Known Exploited Vulnerabilities catalog after both were exploited as zero-days in the wild. CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms both score 10.0 on…
RedHook Android Malware Abuses Wireless ADB for Shell Access
July 12, 2026 Group-IB researchers have uncovered a major upgrade to the RedHook Android malware that abuses Wireless ADB to gain shell privileges on devices without needing a computer connection. Consequently, the threat significantly expands what…
Ghostcommit Prompt Injection Attack Steals Secrets via AI Code Review Blind Spot
July 11, 2026 Researchers from the University of Missouri Kansas City’s ASSET Research Group have disclosed a new supply-chain attack called Ghostcommit. This technique hides malicious prompt-injection instructions inside a PNG image embedded in an…