Security researchers at Group-IB have uncovered a new malware strain called HollowGraph that abuses Microsoft 365 calendar events as a command-and-control channel, targeting Israeli organizations for espionage.
Moxa has published security advisories addressing a Linux kernel vulnerability (CVE-2026-46333) across several industrial product series. The Canadian Cyber Centre recommends users review and apply updates.
Coca-Cola disclosed a ransomware attack on its Fairlife dairy unit in an SEC filing, leading to a temporary production halt in the US. The company says Canadian operations and product safety are unaffected.
A stripped-down privilege escalation exploit for Windows was published on the same day Microsoft issued a record 622 fixes, and researchers fear attackers will quickly turn it into a fully weaponized tool.
The US Department of Justice unsealed an indictment charging three Russian nationals with running bulletproof hosting services that enabled ransomware attacks causing over $62 million in damages, while the EU announced parallel sanctions.
A new phishing wave impersonates LastPass and Bitwarden, using fake DocuSign landing pages to steal credentials. The malicious sites have been taken down as of July 14.
Security researchers found that SpaceXAI's Grok Build tool secretly uploaded entire code repositories to Google Cloud. The company says it has stopped the uploads and will delete all data.
Group-IB researchers detail an updated RedHook Android malware that abuses Wireless ADB to gain shell privileges without root, using Shizuku to execute commands and maintain persistence.
Commvault introduces 'Minutes to Recovery,' a hands-on simulation where participants use frontier AI tools to launch attacks and test their organization's defense and recovery readiness.
Progress Software is emailing ShareFile customers using Storage Zone Controllers to immediately shut down their servers due to a credible external security threat targeting the on-premises file-sharing software.
Broadcom released security advisories between July 8 and 10, 2026, addressing vulnerabilities in multiple VMware Tanzu Greenplum and RabbitMQ products, including some rated as critical.