EN·DE

IT Security

IT Security has the shortest half-life of any category here: vulnerabilities under active exploitation, patches and out-of-band updates, ransomware cases, attacks on hospitals, utilities and public authorities, and the advisories that follow from CISA and its European counterparts. Where a CVE number exists we name it, along with the affected versions and the patch status as it stood when the report was written.

Which is why the date above each report matters — during an ongoing campaign, a three-day-old assessment is out of date even if it was accurate when published. Vulnerabilities in specific products are filed here rather than under Software & Development. What you will not find is instructions for exploiting anything.

Dutch NCSC Warns of Active Exploitation of macOS Screen Sharing Flaw to Deploy Monero Miners

The Netherlands' NCSC reports active attacks exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to install Monero miners on systems with port 5900 exposed.

· 2 sources

Researcher Releases ShieldBreak Zero-Day That Bypasses Microsoft Defender Patch

A researcher published a zero-day exploit that bypasses a recent Microsoft Defender patch, granting SYSTEM privileges on fully patched Windows systems, and reigniting a dispute over disclosure practices.

· 1 source

Anthropic's Claude AI cracks weakened AES and HAWK, raises cyber safety alarm

Anthropic's Claude AI has broken weakened versions of AES and the post-quantum candidate HAWK, while its Mythos 5 model conducted phishing in AISI tests, raising urgent questions about AI-driven cyber threats.

· 6 sources

Check Point discloses authentication bypass in Security Management Servers

Check Point has disclosed a critical authentication bypass vulnerability, CVE-2026-18574, affecting nearly all versions of its Security Management Server and Multi-Domain Security Management Server. No patch is available yet.

· 1 source

Claude Chat Leak: Private Conversations Exposed in Google Search for Third Time

Hundreds of private Claude conversations appeared in Google search results over the weekend, marking the third major AI chatbot share-feature leak in two years.

· 3 sources

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack; Stolen Data Now Public

Coca-Cola confirmed that a ransomware attack on its Fairlife dairy subsidiary led to data theft, and the stolen data is now publicly available after the Anubis gang's deadline expired.

· 3 sources

GitHub and PyPI Roll Out Time-Based Defenses to Thwart Supply-Chain Attacks

GitHub's Dependabot now includes a configurable three-day cooldown before updating packages, while PyPI blocks new file uploads to releases older than 14 days, as the industry shifts toward proactive automated safeguards.

· 1 source

New Malware HollowGraph Uses Microsoft 365 Calendars as Covert C2 Channel, Targets Israeli Organizations

Security researchers at Group-IB have uncovered a new malware strain called HollowGraph that abuses Microsoft 365 calendar events as a command-and-control channel, targeting Israeli organizations for espionage.

· 2 sources

Moxa Issues Security Advisory for Linux Kernel Vulnerability Affecting Multiple Product Lines

Moxa has published security advisories addressing a Linux kernel vulnerability (CVE-2026-46333) across several industrial product series. The Canadian Cyber Centre recommends users review and apply updates.

· 1 source

Coca-Cola Reports Ransomware Attack on Fairlife, Halts US Production

Coca-Cola disclosed a ransomware attack on its Fairlife dairy unit in an SEC filing, leading to a temporary production halt in the US. The company says Canadian operations and product safety are unaffected.

· 2 sources

Researchers Warn of Rapid Weaponization After NightmareEclipse Drops LegacyHive Zero-Day on Record Patch Tuesday

A stripped-down privilege escalation exploit for Windows was published on the same day Microsoft issued a record 622 fixes, and researchers fear attackers will quickly turn it into a fully weaponized tool.

· 2 sources

US and EU Impose Coordinated Sanctions on Russian Bulletproof Hosting Operators Linked to Ransomware Attacks

The US Department of Justice unsealed an indictment charging three Russian nationals with running bulletproof hosting services that enabled ransomware attacks causing over $62 million in damages, while the EU announced parallel sanctions.

· 2 sources

Phishing Campaign Targets LastPass and Bitwarden Users With Fake DocuSign Alerts

A new phishing wave impersonates LastPass and Bitwarden, using fake DocuSign landing pages to steal credentials. The malicious sites have been taken down as of July 14.

· 1 source

Siemens Discloses Vulnerabilities Across 11 Product Lines, Urges Patching

Siemens published security advisories on July 14, 2026, covering 11 product lines. The Canadian Cyber Centre recommends prompt patching.

· 1 source

SpaceXAI's Grok Build Uploaded User Codebases to Cloud, Company Promises Deletion

Security researchers found that SpaceXAI's Grok Build tool secretly uploaded entire code repositories to Google Cloud. The company says it has stopped the uploads and will delete all data.

· 1 source

RedHook Android malware gains shell access via Wireless ADB in new variant

Group-IB researchers detail an updated RedHook Android malware that abuses Wireless ADB to gain shell privileges without root, using Shizuku to execute commands and maintain persistence.

· 1 source

Commvault Launches AI-Powered Cyberattack Simulation for Resilience Training

Commvault introduces 'Minutes to Recovery,' a hands-on simulation where participants use frontier AI tools to launch attacks and test their organization's defense and recovery readiness.

· 1 source

Progress Software Urges ShareFile Admins to Shut Down Servers Over 'Credible' Threat

Progress Software is emailing ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to a credible external security threat targeting the on-premises file-sharing software.

· 1 source

Bitwarden Server Vulnerability Patched in Version 2026.6.2

Bitwarden released a security update for its server product, fixing a vulnerability in versions prior to 2026.6.2. Users are urged to apply the patch.

· 1 source

Broadcom Issues Critical Patches for VMware Tanzu Greenplum and RabbitMQ Products

Broadcom released security advisories between July 8 and 10, 2026, addressing vulnerabilities in multiple VMware Tanzu Greenplum and RabbitMQ products, including some rated as critical.

· 1 source

Palo Alto Networks Patches Critical Buffer Overflow in PAN-OS and Prisma Products

Palo Alto Networks released security updates on July 8, 2026, addressing a buffer overflow vulnerability in PAN-OS and Prisma products, affecting dozens of versions.

· 1 source

Microsoft Patches ‘RoguePlanet’ Zero-Day in Defender After June Patch Tuesday

Microsoft released an emergency security update to fix a critical zero-day vulnerability in Microsoft Defender, dubbed RoguePlanet, which could grant attackers elevated system privileges on Windows.

· 2 sources