IT Security has the shortest half-life of any category here: vulnerabilities
under active exploitation, patches and out-of-band updates, ransomware cases,
attacks on hospitals, utilities and public authorities, and the advisories that
follow from CISA and its European counterparts. Where a CVE number exists we
name it, along with the affected versions and the patch status as it stood when
the report was written.
Which is why the date above each report matters — during an ongoing campaign, a
three-day-old assessment is out of date even if it was accurate when published.
Vulnerabilities in specific products are filed here rather than under
Software & Development. What you will not find is
instructions for exploiting anything.
The Netherlands' NCSC reports active attacks exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to install Monero miners on systems with port 5900 exposed.
A researcher published a zero-day exploit that bypasses a recent Microsoft Defender patch, granting SYSTEM privileges on fully patched Windows systems, and reigniting a dispute over disclosure practices.
Anthropic's Claude AI has broken weakened versions of AES and the post-quantum candidate HAWK, while its Mythos 5 model conducted phishing in AISI tests, raising urgent questions about AI-driven cyber threats.
Check Point has disclosed a critical authentication bypass vulnerability, CVE-2026-18574, affecting nearly all versions of its Security Management Server and Multi-Domain Security Management Server. No patch is available yet.
Hundreds of private Claude conversations appeared in Google search results over the weekend, marking the third major AI chatbot share-feature leak in two years.
Coca-Cola confirmed that a ransomware attack on its Fairlife dairy subsidiary led to data theft, and the stolen data is now publicly available after the Anubis gang's deadline expired.
GitHub's Dependabot now includes a configurable three-day cooldown before updating packages, while PyPI blocks new file uploads to releases older than 14 days, as the industry shifts toward proactive automated safeguards.
Security researchers at Group-IB have uncovered a new malware strain called HollowGraph that abuses Microsoft 365 calendar events as a command-and-control channel, targeting Israeli organizations for espionage.
Moxa has published security advisories addressing a Linux kernel vulnerability (CVE-2026-46333) across several industrial product series. The Canadian Cyber Centre recommends users review and apply updates.
Coca-Cola disclosed a ransomware attack on its Fairlife dairy unit in an SEC filing, leading to a temporary production halt in the US. The company says Canadian operations and product safety are unaffected.
A stripped-down privilege escalation exploit for Windows was published on the same day Microsoft issued a record 622 fixes, and researchers fear attackers will quickly turn it into a fully weaponized tool.
The US Department of Justice unsealed an indictment charging three Russian nationals with running bulletproof hosting services that enabled ransomware attacks causing over $62 million in damages, while the EU announced parallel sanctions.
A new phishing wave impersonates LastPass and Bitwarden, using fake DocuSign landing pages to steal credentials. The malicious sites have been taken down as of July 14.
Security researchers found that SpaceXAI's Grok Build tool secretly uploaded entire code repositories to Google Cloud. The company says it has stopped the uploads and will delete all data.
Group-IB researchers detail an updated RedHook Android malware that abuses Wireless ADB to gain shell privileges without root, using Shizuku to execute commands and maintain persistence.
Commvault introduces 'Minutes to Recovery,' a hands-on simulation where participants use frontier AI tools to launch attacks and test their organization's defense and recovery readiness.
Progress Software is emailing ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to a credible external security threat targeting the on-premises file-sharing software.
Broadcom released security advisories between July 8 and 10, 2026, addressing vulnerabilities in multiple VMware Tanzu Greenplum and RabbitMQ products, including some rated as critical.
Palo Alto Networks released security updates on July 8, 2026, addressing a buffer overflow vulnerability in PAN-OS and Prisma products, affecting dozens of versions.
Microsoft released an emergency security update to fix a critical zero-day vulnerability in Microsoft Defender, dubbed RoguePlanet, which could grant attackers elevated system privileges on Windows.