CM-SEC
  • PROJECT-VICAT
PROJECT-VICAT

The Hacker News • 22nd July 2026

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.

In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.

Patches for the flaw were released by ServiceNow throughout June in the following versions -

Searchlight Cyber, which disclosed ad...
The Hacker News • 22nd July 2026

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

The entry point did not change. Langflow versions before 1.3.0 expose the /api/v1/validate/code endpoint without aut...
The Hacker News • 22nd July 2026

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution...
The Hacker News • 22nd July 2026

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.

That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power modulation on real GPUs and simulated the grid destabilization it could cause.

The technique inverts t...
The Hacker News • 22nd July 2026

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession.

The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock starts, and defenders try to deploy before an attacker finishes reverse-engineering the fix.

For the last thirty-odd years, defenders usua...
The Hacker News • 22nd July 2026

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.

Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA. Everyone fell to at least six of the seven.

The paper went up on arXiv on...
The Hacker News • 22nd July 2026

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

Also patched are four cross-site scripting (XSS) flaws in the Classic Web Client -

Separately, fixes have been rele...
The Hacker News • 22nd July 2026

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.

Successful exploitation of the flaw allows unauthenticated remote atta...
The Hacker News • 22nd July 2026

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.

The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.

"In a network-based attack, an attack...
The Hacker News • 22nd July 2026

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently.

According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot program. CodeMender is an AI-powered agent for vulnerability discovery and patching that was unveiled by th...
The Hacker News • 22nd July 2026

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it.

Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been assigned to it.

Kiro's safety model rests on a human clicking "allow." The agent can run shell comman...
The Hacker News • 22nd July 2026

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees.

404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-founder of EasyOptOuts.

Hide My Email generates unique, random email addresses that forward messages to a user's personal email inbox autom...
Cyber Security News • 22nd July 2026

OpenAI's GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers

Hugging Face has disclosed a security incident that security researchers are calling a watershed moment for AI safety: an autonomous AI agent, built on OpenAI models, independently discovered and chained multiple vulnerabilities, including a zero-day, to breach Hugging Face’s production infrastructure.


The incident occurred during an internal OpenAI evaluation testing the cyber capabilities of GPT-5.6 Sol and an unreleased, more advanced model. Both models had reduced cyber refusals enabled s...
Cyber Security News • 22nd July 2026

Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks

Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181/.182 for Windows and Mac, and 150.0.7871.181 for Linux, with the rollout expected to reach all users over the coming days and weeks.


Several of the fixed flaws could allow attackers to trigger memory corruption, execute arbitrary code, or bypass security validations, making this update a priority patch for...
Cyber Security News • 21st July 2026

Top 10 Malware Used by Hackers Last Week to Launch Cyberattacks

Cybercriminals continued to lean on a familiar arsenal of malware last week, with information stealers and remote access trojans (RATs) dominating the threat landscape as the primary tools for initial access, credential theft, and long-term system control.


Topping the list is Vidar, an infostealer that logged 282 detections, narrowly edging out AsyncRAT, a widely abused open-source RAT that recorded 275 hits despite a sharp weekly decline. Remcos and XWorm rounded out the top four with 195 an...
Cyber Security News • 21st July 2026

Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers.


The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a bug class that has repeatedly plagued SharePoint in 2026.


CVE-2026-50522 affects on-premises x64 deployments of Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint...
Cyber Security News • 21st July 2026

Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel

A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool also uses DNS AAAA responses as a fallback channel to restore Microsoft Graph credentials when cloud authentication fails.


Kaspersky researchers have associated the activity with highly targeted cyberespionage operations against Israeli organizations. While the broader CAV3RN ecosystem has been connect...
Cyber Security News • 21st July 2026

Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection

The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, drivers, and security components.


This rapid wave of Common Vulnerabilities and Exposures (CVE) announcements underscores how automated and AI-assisted code analysis is accelerating vulnerability discovery while creating significant patch management challenges for Linux...
Cyber Security News • 21st July 2026

Now You Can teach a Skill to Claude by Just Recording your Screen

Anthropic has rolled out a new capability in Claude Cowork that lets users teach the AI assistant a repeatable skill simply by recording their screen while performing a task.


The feature, called “Record a skill,” turns a screen capture into a workflow Claude can execute on demand, eliminating the need to write manual instructions or scripts.


The image shared shows the feature in action within the Claude desktop app interface, where users can select “Record a skill” from the plus menu.


U...
Cyber Security News • 21st July 2026

APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.


The campaign has targeted senior government and defense officials, policy experts, and, in some cases, family members connected to high-value individuals.


Rather than relying on large volumes of suspicious emails, the group builds trust through realistic invitations, extended conversations, and messages sent...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Siemens Opcenter X | CISA

View CSAF
Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version.
The following versions of Siemens Opcenter X are affected:
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT envir...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Rockwell Automation FactoryTalk Services Platform | CISA

View CSAF
Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.
The following versions of Rockwell Automation FactoryTalk Services Platform are affected:

CVE-2026-10714

A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the applicati...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Siemens CADRA | CISA

View CSAF
CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens CADRA are affected:
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operat...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Rockwell Automation Studio 5000 Logix Designer | CISA

View CSAF
Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code.
The following versions of Rockwell Automation Studio 5000 Logix Designer are affected:
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
CISA recommends users take defensive measures to minimize the risk of exploitation of...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Rockwell Automation 1718-AENTR/1719-AENTR | CISA

View CSAF
Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected:

CVE-2026-9140

A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.

Affected Prod...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Rockwell Automation 1734 POINT I/O | CISA

View CSAF
Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
The following versions of Rockwell Automation 1734 POINT I/O are affected:

CVE-2026-10573

A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.

Affected Products
Rockwell Automation 1...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW | CISA

View CSAF
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW are affected:
As a general security measure, Siemens str...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Siemens IAM Client | CISA

View CSAF
Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens IAM Client are affected:
As a general se...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importa...
Cybersecurity and Infrastructure Security Agency C • 22nd July 2026

Siemens SIDIS Secured SmartPlug | CISA

View CSAF
SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version.
The following versions of Siemens SIDIS Secured SmartPlug are affected:
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operat...

© 2026 CM-SEC, LLC. All rights reserved.