// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSEC

Microsoft: AI Will Make Patch Tuesday Permanently More Demanding

Microsoft EVP Pavan Davuluri confirmed on July 9, 2026 that AI will permanently increase the volume of security updates in each Patch…

Jul 10, 2026views - 1.7k

news

Ex-DigitalMint Negotiator Gets 70 Months for Feeding Clients to BlackCat

Angelo Martino was sentenced to 70 months in prison for acting as an insider for the BlackCat/ALPHV ransomware gang against five U.S.…

Jul 10, 2026views - 1.5k

malware

GigaWiper: The Post-Compromise Malware Masking Three Destructive Intents

GigaWiper is a modular Go backdoor that unifies wiper, fake ransomware, and spyware capabilities. Linked to BLUERABBIT, the platform c…

Jul 09, 2026views - 1.3k

ransomware

LVM: Weeks of Blackout After Ransomware Hits System Unpatched for Two Years

Latvia's state-owned forestry company Latvijas valsts meži (LVM) remains paralyzed weeks after a June 22 ransomware attack. Roughly tw…

Jul 09, 2026views - 1.3k

CYBERSEC

AI-Generated Malware Maps Active Directory: How It Was Caught

On June 3, 2026, Huntress detected an attack using an AI-generated PowerShell script created via vibe coding. Behavioral detection suc…

Jul 09, 2026views - 1.2k

CYBERSECZERO-DAY

Microsoft Patches RoguePlanet: When the Antivirus Becomes the Attack Surface

CVE-2026-50656 enables privilege escalation to SYSTEM via the Microsoft Defender engine. The fix arrives through an automatic engine u…

Jul 09, 2026views - 1.4k

CYBERSEC

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered

A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Jul 09, 2026views - 1.4k

ransomware

Hyadina Strikes with GodDamn: Microsoft-Signed Driver Disables EDR in 24 Hours

The Hyadina ransomware-as-a-service group deploys a new locker, GodDamn, using the Microsoft-signed PoisonX kernel driver to neutraliz…

Jul 09, 2026views - 2k

CYBERSEC

Verified X Ads Spread Mac Malware and Steal Microsoft 365 Accounts

Active campaigns exploit X's blue verification badge to distribute Mac malware via ClickFix and steal Microsoft 365 OAuth tokens using…

Jul 09, 2026views - 1.8k

ransomware

Mount Royal University Confirms Breach With Double Extortion: Data Theft and Deletion

The CMD Organization ransomware group claimed responsibility for the attack on Mount Royal University, demanding a $1.9 million ransom…

Jul 09, 2026views - 1.8k

agentic

Agentic AI: A Lone Attacker Compromises Enterprise AWS in 72 Hours

Sygnia documents the first operational case of a lone threat actor using AI-assisted workflows to compress an enterprise AWS attack fr…

Jul 08, 2026views - 1.4k

VULNCRITICAL

Lorex 0-Day ZDI-26-399: Root RCE on Wi-Fi Camera, No Patch After 14 Months

The ZDI-26-399 vulnerability exposes Lorex 2K Indoor Wi-Fi Security Cameras to root-level remote code execution from the local network…

Jul 08, 2026views - 1.3k

aiZERO-DAY

Ollama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk

ZDI has disclosed a zero-day vulnerability in Ollama enabling unauthenticated remote denial-of-service attacks via the downloadBlob fu…

Jul 08, 2026views - 1.5k

CYBERSECEXPLOIT

FortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It

CISA estimates 74,000 Fortinet devices have compromised credentials. The FortiBleed campaign exploits credential reuse and brute-force…

Jul 08, 2026views - 1.5k

ai

HalluSquatting Turns AI Assistants' Predictable Hallucinations into a Botnet Installation Vector

Researchers from Tel Aviv University, Technion, and Intuit demonstrated that nine AI coding tools install botnet malware when asked fo…

Jul 08, 2026views - 1.4k

CYBERSEC

Qualys Unveils Risk Operations Center for the 'Day Minus Seven' Era

Qualys published a product-tech blog post on July 8, 2026 introducing the Risk Operations Center (ROC) as an operational response to w…

Jul 08, 2026views - 1.3k

CYBERSECCVE

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow

An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

Jul 08, 2026views - 1.5k

CYBERSEC

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed

ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

Jul 08, 2026views - 1.3k

CYBERSECEXPLOIT

IRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup

IRIS C2, a McLean, Virginia startup offering up to $7 million for zero-day vulnerabilities, is operated by Jacob Wohl and Jack Burkman…

Jul 08, 2026views - 1.7k

CYBERSECZERO-DAY

KDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses

KDDI confirmed a zero-day attack in third-party software compromised the shared email platform of five Japanese ISPs, exposing over 12…

Jul 08, 2026views - 1.5k

CYBERSECCVE

Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi OS

Ubiquiti released security updates on July 8, 2026 for seven critical vulnerabilities in UniFi OS. The most severe, CVE-2026-50746, ca…

Jul 08, 2026views - 1.9k

linuxEXPLOIT

GhostLock: 15-Year Linux Kernel Bug Now Publicly Exploitable, Guarantees Root

CVE-2026-43499 enables root escalation and container escape on nearly every Linux distribution since 2011. Nebula Security published t…

Jul 08, 2026views - 1.4k

CYBERSECEXPLOIT

Gartner: By 2028, 60% of Enterprises Will Drop Annual Pentesting for Continuous Validation

Gartner formalizes the COST framework for continuous vulnerability validation. Exploit time has compressed to under 10 hours, and 53%…

Jul 08, 2026views - 1.3k

malware

RedWing: Android Banking Malware Turns into a Telegram Rental Service

Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

Jul 08, 2026views - 1.3k