{"date_iso":"2026-07-31","date_human":"Friday, July 31, 2026","generated_utc":"2026-07-31 16:24 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined","link":"https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News","Wired Security"],"coverage":6,"cve_ids":[],"summary":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx/s1600/chrome.jpg","description":"Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the","related":[{"title":"Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities","link":"https://cybersecuritynews.com/google-ai-fixes-chrome-vulnerabilities/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace","link":"https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Google says AI helped Chrome fix 1,072 security bugs in two releases","link":"https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting","link":"https://www.wired.com/story/chrome-needs-twice-a-week-patching-thanks-to-ai-bug-hunting-for-now/","source":"Wired Security","date_rel":"23h ago"},{"title":"ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories","link":"https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"30 Jul"}]},{"title":"Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database","link":"https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html","reason":"Azure","category":"News","sources":["Microsoft Security","SecurityWeek","The Hacker News","Wiz Research"],"coverage":4,"cve_ids":["CVE-2026-24304","CVE-2026-66803"],"summary":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_dFT-y76kGOf4rFOAu6NYNsE2s57G-7dl0a03tULY-f2ZGTbpPeEvu-NUCLVh-bgEdBvecIt28BJLQXUHclBc_IfGP9tBSZyMIm971Myrp2_zhSPyXhCJkhYmSfvLWNRewSsCip2YJfBEWocEEKdXPUL-y_mK8ZcHbBAaTWt8SzXmDJeQoYc6r5ceC6A/s1600/wiz-cosmodb.jpg","description":"A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a","related":[{"title":"Critical Flaw Allowed to Azure Cosmos DB Pwnage","link":"https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304","source":"Microsoft Security","date_rel":"30 Jul"},{"title":"CosmosEscape: Taking Over Every Database in Azure Cosmos DB","link":"https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db","source":"Wiz Research","date_rel":"30 Jul"}]},{"title":"USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports","link":"https://www.darkreading.com/identity-access-management-security/usa-fencing-hidden-identity-challenge-amateur-sports","reason":"Teams","category":"News","sources":["CrowdStrike Blog","Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.","source":"Dark Reading","date_rel":"3h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt66a2e6a794ec3f06/6a6b70a2c08842d09cba7462/USA_Fencing-Jumio_Bala_Kumar.png?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Claude Mythos \u2014 Hype vs. Reality: What Security Teams Need to Know","link":"https://www.darkreading.com/cybersecurity-operations/claude-mythos-hype-vs-reality","source":"Dark Reading","date_rel":"30 Jul"},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"30 Jul"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"29 Jul"},{"title":"73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack","link":"https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html","source":"The Hacker News","date_rel":"29 Jul"},{"title":"Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud","link":"https://www.crowdstrike.com/en-us/blog/new-in-falcon-cloud-security-helping-security-teams-move-faster/","source":"CrowdStrike Blog","date_rel":"29 Jul"}]},{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Dark Reading","Elastic Security Labs","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after\u2026","source":"The Hacker News","date_rel":"30 Jul","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-BgxoTGLqXYzQh4HW0TUm-hbX0ApFizzFtFkKe5mb3fKS_yn6Zzpj_Uvivxi7VCwEUOuJx3Bg1XHpHWq9tbZh5xBrAHT4gBG2DYyqvFkVKmWIRiF_zCpXIG5bTs7HfsV1pjM2EsTm-e7WttN-iB57p0n4ki2Vs7vXyB6rTF9mSqlwPu3h7KHocg0mWcI/s1600/copilot-word.jpg","description":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. M\u00e5l\u00f8y's","related":[{"title":"Malwarebytes for Windows, now available on the Microsoft Store","link":"https://www.malwarebytes.com/blog/product/2026/07/malwarebytes-for-windows-now-available-on-the-microsoft-store","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Microsoft Teams vishing attacks lead to Chaos ransomware attacks","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/","source":"Bleeping Computer","date_rel":"30 Jul"},{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"30 Jul"},{"title":"Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation","link":"https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here","link":"https://www.elastic.co/security-labs/sentinel-detection-rules-migration","source":"Elastic Security Labs","date_rel":"29 Jul"},{"title":"'Certighost' Flaw Haunts Microsoft Active Directory Certificates","link":"https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates","source":"Dark Reading","date_rel":"28 Jul"}]},{"title":"Google Earth\u2019s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images","link":"https://www.404media.co/google-earths-new-ai-lets-anyone-fabricate-completely-bullshit-satellite-images/","reason":"Google","category":"News","sources":["404 Media","CCCS Alerts & Advisories","Wiz Research"],"coverage":3,"cve_ids":[],"summary":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a\u2026","source":"404 Media","date_rel":"4m ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/CleanShot-2026-07-31-at-08.53.48.gif","description":"On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a drone strike to manifesting a nuclear plant in Iran. Usually, Google Earth is an exceptionally useful tool for open source intelligence (OSINT) analysts to digitally monitor areas of interest and see how they change over time, say, during a conflict or disaster. Now, Google Earth can easily be used as a tool for disinformation. In 404 Media\u2019s tests, we were able to add\u2026","related":[{"title":"Google security advisory (AV26-768)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-768","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","source":"Wiz Research","date_rel":"29 Jul"}]},{"title":"Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely \u2013 Update Now","link":"https://cybersecuritynews.com/jetbrains-vulnerability-execute-malicious-code/","reason":"CVE-2026-63077","category":"News","sources":["Cyber Security News","Rapid7 Blog","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-63077"],"summary":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/Critical-JetBrains-Vulnerability-Allow-Attackers-to-Execute-Malicious-Code-Remotely-Update-Now-.webp","description":"JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access. According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating\u2026","related":[{"title":"Critical Code Execution Vulnerability Patched in TeamCity","link":"https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity","link":"https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity","source":"Rapid7 Blog","date_rel":"29 Jul"}]},{"title":"North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials","link":"https://cybersecuritynews.com/north-korean-etherhiding-campaign/","reason":"Macos","category":"News","sources":["Cyber Security News","Palo Alto Unit 42","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/North-Korean-EtherHiding-Campaign-Targets-Crypto-Wallets-and-Developer-Credentials.webp","description":"A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine web search into a possible entry point for a serious compromise. The attack begins with a ClickFix-style lure that makes a browser page look like a frozen or rebooting Mac. Victims are told to open Terminal and paste a command that the malicious page has already copied to their clipboard, allowing the infection chain to start. AllSecure analysts identified the activity while\u2026","related":[{"title":"The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version","link":"https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/","source":"Palo Alto Unit 42","date_rel":"6h ago"},{"title":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware","link":"https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html","source":"The Hacker News","date_rel":"21h ago"}]},{"title":"BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations","link":"https://cybersecuritynews.com/blacktech-apt-deploys-blueshell-linux-backdoor/","reason":"Linux","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Schneier on Security"],"coverage":3,"cve_ids":[],"summary":"BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/BlackTech-APT-Deploys-BlueShell-Linux-Backdoor-Against-Japanese-Organizations.webp","description":"BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to run commands, move files, and route traffic after they have already entered a network, raising the risk to internal systems and sensitive data. The attack begins after the attackers gain access and move laterally through the victim environment using SSH. From there, they deploy a loader that launches the backdoor, a method that reflects the group\u2019s established interest in\u2026","related":[{"title":"SSH Bot Profiles Linux CPU, GPU and RAM Before Deploying Cryptocurrency Miner","link":"https://cybersecuritynews.com/ssh-bot-profiles-linux-cpu/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"Cryptominer Abuses Linux PAM to Hide From SOC Analysts","link":"https://www.infosecurity-magazine.com/news/xmrig-linux-pam-forensic/","source":"Infosecurity Magazine","date_rel":"30 Jul"},{"title":"Long-Lived Vulnerability in Microsoft Secure Boot","link":"https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html","source":"Schneier on Security","date_rel":"29 Jul"}]},{"title":"ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans","link":"https://cybersecuritynews.com/shuttergap-exposes-millions-of-aws-resources/","reason":"Aws","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify risky configurations. However, new research from Aryon Security\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/ShutterGap-Exposes-Millions-of-AWS-Resources-Between-Cloud-Security-Scans.webp","description":"Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify risky configurations. However, new research from Aryon Security reveals that this approach may overlook a significant class of threats: temporary AWS resources that are publicly exposed but removed before the next scan occurs. Aryon refers to this visibility gap as \u201cShutterGap.\u201d It happens when a cloud resource is made public for a brief period, sometimes lasting only a few minutes. Attackers can continuously monitor public AWS resources\u2026","related":[{"title":"AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks","link":"https://www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"CareCloud Data Breach Impacts Over 350,000","link":"https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/","source":"SecurityWeek","date_rel":"8h ago"}]},{"title":"North Korean hackers behind major open-source supply chain attacks, Amazon says","link":"https://therecord.media/north-korea-hackers-amazon-malware","reason":"Amazon","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.","source":"The Record","date_rel":"30 Jul","thumbnail":"http://cms.therecord.media/uploads/Javascript_ebfda374da.jpg","description":"","related":[{"title":"Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers","link":"https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Amazon Links Debug and Chalk npm Hijack to North Korea\u2019s Sapphire Sleet","link":"https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html","source":"The Hacker News","date_rel":"30 Jul"},{"title":"A little-known npm package was North Korea\u2019s warm-up act for the axios hack","link":"https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/","source":"CyberScoop","date_rel":"29 Jul"}]}],"worth_reading":[{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"30 Jul","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"VMware fixes three critical flaws allowing auth bypass, VM escapes","link":"https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"29 Jul"}]},{"title":"Max-severity Exchange server flaw under active exploitation by Kremlin hackers","link":"https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/","reason":"Exchange","category":"Media","sources":["Ars Technica Security","Bleeping Computer"],"coverage":2,"cve_ids":[],"summary":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security\u2026","source":"Ars Technica Security","date_rel":"19h ago","thumbnail":"https://cdn.arstechnica.net/wp-content/uploads/2023/07/exploit-vulnerability-security-500x500.jpg","description":"Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook\u2019s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday . Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email\u2026","related":[{"title":"Russian hackers exploit Exchange OWA zero-day for long-term mailbox access","link":"https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/","source":"Bleeping Computer","date_rel":"29 Jul"}]},{"title":"ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-495/","reason":"Vmware","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to\u2026","source":"Zero Day Initiative","date_rel":"29 Jul","thumbnail":"","description":"This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-47876.","related":[{"title":"VMware security advisory (AV26-763)","link":"https://cyber.gc.ca/en/alerts-advisories/vmware-security-advisory-av26-763","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-66803","vendor":"Microsoft","product":"Azure Cosmos DB","severity":"CRITICAL","score":10.0,"description":"Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-66803"},{"id":"CVE-2026-18452","vendor":"Rich Source","product":"DMS+ (Non-Mobile)","severity":"CRITICAL","score":10.0,"description":"DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18452"},{"id":"CVE-2026-13435","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.9,"description":"IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13435"},{"id":"CVE-2026-12946","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.9,"description":"IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":0.0034,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12946"},{"id":"CVE-2026-28323","vendor":"SolarWinds","product":"Web Help Desk","severity":"CRITICAL","score":9.8,"description":"SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0064,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28323"},{"id":"CVE-2026-4978","vendor":"UMAI Vision","product":"Traffic Analysis System","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection.\n\nThis issue affects Traffic Analysis System: from 30 before 34.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-4978"},{"id":"CVE-2026-12940","vendor":"IBM","product":"Langflow OSS","severity":"CRITICAL","score":9.8,"description":"IBM Langflow OSS 1.0.0 through 1.10.1\u00a0 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0048,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12940"},{"id":"CVE-2026-12118","vendor":"IBM","product":"webMethods Integration (on prem)","severity":"CRITICAL","score":9.8,"description":"IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.005,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12118"},{"id":"CVE-2026-12943","vendor":"IBM","product":"HMC V10.3.1050.0","severity":"CRITICAL","score":9.8,"description":"IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0092,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12943"},{"id":"CVE-2026-67208","vendor":"somta","product":"Juggle","severity":"CRITICAL","score":9.8,"description":"Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attack\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.011,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67208"}],"vendor_spikes":[{"vendor":"HashiCorp","count":56,"critical_count":1},{"vendor":"WordPress","count":37,"critical_count":1},{"vendor":"Unknown","count":25,"critical_count":3},{"vendor":"IBM","count":23,"critical_count":5},{"vendor":"Red Hat","count":19,"critical_count":0},{"vendor":"Apache","count":16,"critical_count":0},{"vendor":"Microsoft","count":6,"critical_count":1},{"vendor":"SGLang","count":6,"critical_count":0},{"vendor":"cloudreve","count":6,"critical_count":0},{"vendor":"MZ Automation GmbH","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":293,"has_news_data":true,"has_cve_data":true}