EN·DE

IT Security

New Malware HollowGraph Uses Microsoft 365 Calendars as Covert C2 Channel, Targets Israeli Organizations

Security researchers at Group-IB have uncovered a new malware strain called HollowGraph that abuses Microsoft 365 calendar events as a command-and-control channel, targeting Israeli organizations for espionage.

· 2 sources

Moxa Issues Security Advisory for Linux Kernel Vulnerability Affecting Multiple Product Lines

Moxa has published security advisories addressing a Linux kernel vulnerability (CVE-2026-46333) across several industrial product series. The Canadian Cyber Centre recommends users review and apply updates.

· 1 source

Coca-Cola Reports Ransomware Attack on Fairlife, Halts US Production

Coca-Cola disclosed a ransomware attack on its Fairlife dairy unit in an SEC filing, leading to a temporary production halt in the US. The company says Canadian operations and product safety are unaffected.

· 2 sources

Researchers Warn of Rapid Weaponization After NightmareEclipse Drops LegacyHive Zero-Day on Record Patch Tuesday

A stripped-down privilege escalation exploit for Windows was published on the same day Microsoft issued a record 622 fixes, and researchers fear attackers will quickly turn it into a fully weaponized tool.

· 2 sources

US and EU Impose Coordinated Sanctions on Russian Bulletproof Hosting Operators Linked to Ransomware Attacks

The US Department of Justice unsealed an indictment charging three Russian nationals with running bulletproof hosting services that enabled ransomware attacks causing over $62 million in damages, while the EU announced parallel sanctions.

· 2 sources

Phishing Campaign Targets LastPass and Bitwarden Users With Fake DocuSign Alerts

A new phishing wave impersonates LastPass and Bitwarden, using fake DocuSign landing pages to steal credentials. The malicious sites have been taken down as of July 14.

· 1 source

Siemens Discloses Vulnerabilities Across 11 Product Lines, Urges Patching

Siemens published security advisories on July 14, 2026, covering 11 product lines. The Canadian Cyber Centre recommends prompt patching.

· 1 source

SpaceXAI's Grok Build Uploaded User Codebases to Cloud, Company Promises Deletion

Security researchers found that SpaceXAI's Grok Build tool secretly uploaded entire code repositories to Google Cloud. The company says it has stopped the uploads and will delete all data.

· 1 source

RedHook Android malware gains shell access via Wireless ADB in new variant

Group-IB researchers detail an updated RedHook Android malware that abuses Wireless ADB to gain shell privileges without root, using Shizuku to execute commands and maintain persistence.

· 1 source

Commvault Launches AI-Powered Cyberattack Simulation for Resilience Training

Commvault introduces 'Minutes to Recovery,' a hands-on simulation where participants use frontier AI tools to launch attacks and test their organization's defense and recovery readiness.

· 1 source

Progress Software Urges ShareFile Admins to Shut Down Servers Over 'Credible' Threat

Progress Software is emailing ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to a credible external security threat targeting the on-premises file-sharing software.

· 1 source

Bitwarden Server Vulnerability Patched in Version 2026.6.2

Bitwarden released a security update for its server product, fixing a vulnerability in versions prior to 2026.6.2. Users are urged to apply the patch.

· 1 source

Broadcom Issues Critical Patches for VMware Tanzu Greenplum and RabbitMQ Products

Broadcom released security advisories between July 8 and 10, 2026, addressing vulnerabilities in multiple VMware Tanzu Greenplum and RabbitMQ products, including some rated as critical.

· 1 source