Security · Top stories
Apple Patches 'Hide My Email' Vulnerability After Year of Exposure
Apple has fixed a vulnerability in its 'Hide My Email' feature that exposed users' real email addresses for over a year. The flaw, first reported in June 2025, was only addressed after recent media coverage and a class-action lawsuit. This fix is crucial for maintaining user privacy and trust in Apple's privacy tools.
Critical WordPress Vulnerabilities Exploited, Urgent Patching Advised
Two critical vulnerabilities, CVE-2026-60137 and CVE-2026-63030, in WordPress Core are being actively exploited, affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. These 'wp2shell' flaws allow remote code execution through anonymous requests, prompting WordPress to issue updates 6.9.5 and 7.0.2 on July 17, 2026, with forced auto-updates enabled. Cloudflare has deployed Web Application Firewall protections to mitigate the risk while users apply patches.
Langflow Vulnerabilities Exploited by AI Agents for Ransomware Attacks
Langflow vulnerabilities CVE-2025-3248 and CVE-2026-55255 are being exploited in separate security incidents. JadePuffer's AI agent uses CVE-2025-3248 for automated ransomware attacks against AI infrastructures, while CISA orders fixes for CVE-2026-55255 affecting government systems.
Suno AI Breach Exposes Music Scraping Practices and User Data
Suno AI experienced a substantial data breach in November 2025, exposing the scope of its music scraping practices and compromising user data. The hacker accessed Suno's source code, showing the AI was trained using music and lyrics scraped from YouTube, Deezer, Genius, and other sources. This breach highlights the ongoing legal challenges Suno is facing regarding its use of copyrighted materials for AI training.
Apple Sues OpenAI Over Alleged Trade Secret Theft in Hardware Development
Apple has filed a lawsuit against OpenAI, alleging the AI company stole trade secrets through the hiring of former Apple employees to aid in developing its hardware products. The lawsuit mentions OpenAI's Chief Hardware Officer Tang Tan and former Apple engineer Chang Liu as central figures in the alleged misconduct. This legal conflict signifies ongoing tension and competition in the tech industry regarding intellectual property.
Google's Gemini Platform Expands with Remote MCP Server and CLI Vulnerability
Google's Gemini Enterprise Agent Platform now supports a remote Managed Control Plane (MCP) server, enabling secure connections between external AI agents and Google Cloud. Additionally, a vulnerability in the Gemini CLI was exploited by a hacker to manage a botnet, revealing security concerns in open-source AI tools. The updates aim to streamline agent development while ensuring compliance and data protection.
CISA Urges Patch of Actively Exploited Microsoft SharePoint Vulnerabilities
CISA added CVE-2026-45659, an actively exploited RCE vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog. This flaw enables authenticated attackers to execute code without elevated privileges on SharePoint servers. It emphasizes the need for urgent patching, especially for federal agencies.
Zimbra Releases Critical Security Patches for Classic Web Client
Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.
CISA Issues Guidance on Zero Trust for Critical Infrastructure Security
CISA has released new guidance emphasizing the implementation of Zero Trust principles in critical infrastructure security. This guidance aims to mitigate threats from state-sponsored actors exploiting identity vulnerabilities, especially in operational technology environments.
US military apps found with Chinese and Russian code raise data security concerns
A study found that over 12% of mobile apps aimed at US military personnel contain code from Chinese and Russian companies, increasing risks of data harvesting by adversary nations. This poses potential risks to service members' safety and operational security, particularly as previous investigations highlighted vulnerabilities in location tracking of troops.
Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday
Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.
HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications
HollowGraph, a new malware, uses Microsoft 365 calendar events dated to 2050 for command-and-control and data exfiltration. This method disguises traffic as legitimate, targeting Israeli entities and linked to Iranian threat actors.
DOJ Seizes Over 1,000 Domains for Illegal World Cup Streaming
The U.S. Department of Justice seized and blocked over 1,000 domains during the World Cup for illegal streaming. This action aims to protect intellectual property and consumers from potential security threats associated with unauthorized streaming sites.
Cloudflare and Patreon Partner to Block Unauthorized AI Crawlers and Monetize Content
Cloudflare announced updates to their policies and tools, including blocking mixed-use AI crawlers by default from September 15, 2026, to help website owners manage AI traffic and monetize their content. Patreon has joined forces with Cloudflare to block AI crawlers from accessing creator content. The move aligns with industry shifts towards AI-dominated web traffic and aims to protect content owners' intellectual property.
AI Speeds Up Exploit Development Post-Patching, Threatening Cybersecurity
Anthropic's AI, Claude Mythos, can reverse-engineer patches into exploits in under an hour, disrupting traditional timelines for vulnerability exploitation. This significant shift means defenders have far less time to secure systems before attackers can exploit known vulnerabilities, raising serious concerns about the effectiveness of current patching strategies.
Researchers Present Bit2Watt Attack Threatening Power Grids via Cloud GPUs
Three researchers from Zhejiang University revealed the Bit2Watt attack, enabling cloud tenants to destabilize power grids using GPU workloads without requiring exploits. This method poses a significant risk as it leverages legitimate compute functions to create controlled power oscillations that can threaten infrastructure stability.
Flock Cameras Expand Surveillance Across U.S., Sparking Privacy Concerns
Law enforcement agencies across the U.S. are using Flock cameras, initially for vehicle tracking, to search for individuals through detailed descriptions. This usage extends beyond license plate recognition, incorporating AI to track people based on physical characteristics or affiliations. The widespread deployment of 90,000 cameras has raised significant privacy concerns due to lack of public consent.
Judge Dismisses Lawsuit Against Apple Over iCloud CSAM Detection
A lawsuit accusing Apple of not preventing child sexual abuse material (CSAM) on iCloud was dismissed by a California judge. The company was ruled immune under Section 230, shielding it from liability for user-uploaded content. The case highlights ongoing debates about tech companies' roles in moderating content on their platforms.
Qilin Ransomware Gang Exploits Patched PAN-OS VPN Vulnerability
The Qilin ransomware gang is exploiting a critical flaw (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect to gain unauthorized access and deploy ransomware. Despite the vulnerability being patched on May 13, 2026, attacks have led to network breaches and data encryption. The U.S. CISA has urged federal agencies to secure their GlobalProtect instances immediately.
Critical ServiceNow Flaw Exploited Despite Patch Release
A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.
Violent Online Network '764' Linked to Youth Criminality Across Multiple Countries
A 14-year-old boy in Sweden was linked to an online network called 764, which promotes youth violence and extortion through games like Roblox and Minecraft. This network, founded by a Texas teen, is tied to a growing trend of victims becoming perpetrators under online influence, highlighting systemic issues across global digital communities.
Estée Lauder Data Breach Exposes Sensitive Details Through Oracle E-Business Vulnerability
Estée Lauder disclosed a significant data breach resulting from the exploitation of a zero-day vulnerability in Oracle E-Business Suite. The attack occurred in August 2025 and was revealed in June 2026, impacting personal data including Social Security numbers, financial, and health information of employees. The breach was connected to the Cl0p cybercrime group and affected multiple companies.
Researchers Uncover ClickFix Social Engineering Exploits Fueling Malware Campaigns
Bert-Jan Pals has uncovered a sophisticated method of malware delivery via ClickFix, using API-driven servers to evade detection. The ClickFix tactic manipulates user habits through fake CAPTCHAs, enabling attackers to deliver various malware, impacting Microsoft 365 accounts and Mexican banks. This reveals a growing threat to cybersecurity, exploiting common user behaviors for infiltration.
Adobe and CISA Urgently Address Critical ColdFusion Flaws Amid Exploitation
Adobe has released patches to fix critical vulnerabilities in ColdFusion, including CVE-2026-48282, which allow for arbitrary code execution and are actively exploited. CISA has added these flaws to its Known Exploited Vulnerabilities catalog and mandated federal agencies to apply patches immediately. The exploitation underscores the critical need for organizations using ColdFusion to promptly update their systems.
Meta Faces $1.4 Trillion in State Lawsuits and EU Fines for Addictive Social Media Designs
Meta is facing potential penalties from four US states totaling $1.4 trillion due to alleged addictive features on Facebook and Instagram. Additionally, the EU has accused Meta of breaching the Digital Services Act with these features, threatening fines up to 6% of its global annual turnover. The cases highlight concerns about the mental and physical wellbeing effects of Meta's platforms on users, particularly minors.
U.S. Executive Order Mandates Post-Quantum Encryption by 2030
President Trump signed Executive Order 14412, requiring federal agencies to transition to post-quantum encryption by December 31, 2030, and authentication by December 31, 2031. This move addresses the imminent threat quantum computing poses to traditional cryptographic systems, stimulating the broader tech industry's shift towards post-quantum technologies.
Meta's AI support assistant exploited for 20,000 account takeovers
Attackers hijacked over 20,000 Instagram accounts using Meta's AI assistant without exploits or password guessing. The assistant confirmed operations based on an interaction, highlighting vulnerabilities of AI agents in authorization processes.
Oshkosh Cancels Flock Safety Contract After False Statements by Company
The Oshkosh City Council revoked its contract with Flock Safety after the company falsely claimed its ALPR system did not create heat maps of vehicle movements. This incident highlights a broader pattern of misleading statements from Flock regarding its technology and privacy practices, raising significant concerns over its credibility in the law enforcement technology sector.
AliExpress Fined €550 Million for Selling Counterfeit and Unsafe Products
AliExpress has been fined €550 million ($629 million) by the European Commission for failing to prevent the sale of illegal and counterfeit products, marking the largest fine under the Digital Services Act. The investigation revealed shortcomings in product verification and removal processes, posing risks to consumer safety. This fine underscores the EU's commitment to stringent e-commerce regulations.
FCC Fines and Plans Ban on DJI-Tech Disguised Products Citing National Security
The FCC has fined eight companies $25,000 each for not responding to inquiries about their use of DJI technology. The Commission plans a retroactive ban on their drones and cameras, given concerns over evading foreign drone bans. This crackdown reflects national security concerns involving disguised DJI tech in the US.
Node.js to release security updates for multiple versions on July 27, 2026
The Node.js project plans to release security updates for versions 26.x, 24.x, and 22.x on July 27, 2026. The updates will address high severity security vulnerabilities, emphasizing the need for users to maintain up-to-date software for system security.
Ostium platform suffers $23.7M theft in off-chain attack
Ostium trading platform experienced a $23.75 million theft due to price manipulation via compromised off-chain infrastructure. The incident has halted trading operations as the platform works on security measures and assessing impacts for liquidity providers.
Four AI coding agents affected by sandbox escape vulnerabilities
Security researchers have demonstrated sandbox escape vulnerabilities in Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity. These vulnerabilities exploit file interactions that allow the sandboxed agents to trigger commands outside their protected environment, highlighting significant security shortcomings in AI coding tools.
SecurityWeek Introduces Critical Impact Awards for Industrial Cybersecurity
SecurityWeek has launched the Critical Impact Awards to recognize achievements in industrial cybersecurity. This awards program aims to honor organizations and individuals based on merit rather than sponsorship, enhancing credibility in the cybersecurity field.
Kenya investigates hack of president's website demanding bitcoin ransom
Kenya is investigating a cyberattack that defaced President William Ruto's official website with a ransom demand of five bitcoins. The attackers claimed this was their third warning to the president, though no sensitive data has been compromised according to government officials.
Researchers Reveal Security Flaws in AI Coding Agents and Open-Source Mobile Frameworks
Researchers from Hong Kong University have highlighted vulnerabilities in AI coding agents, notably OpenAI Codex and Claude Code, which can be bypassed using techniques like SKILLCLOAK. These techniques allow malicious AI add-ons and agents to evade current security scanners. These findings underscore the need for improved security measures in AI agent marketplaces and software, as current defenses are inadequate.
CISO Andreas Gaetje Discusses Career Path at Körber AG
Andreas Gaetje, CISO at Körber AG, reflects on his unconventional career journey from economics to cybersecurity. He emphasizes the significance of adapting to the evolving role of IT security, which has grown from compliance to a critical business threat.
Meta Awards $78,000 Bug Bounty for Critical Customer Support Data Vulnerability
Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.
Clover Health Investments Reports Data Breach Affecting Customer Information
Clover Health Investments disclosed a data breach affecting customers' personal and health information due to a social engineering attack that compromised three employee accounts. The company initiated its response plan and engaged cybersecurity experts to handle the situation, though the full impact of the breach is still being investigated.
Taiwan indicts ex-TSMC manager over alleged leakage of chip secrets to China
Taiwanese prosecutors indicted a former TSMC deputy manager for allegedly stealing 21 confidential chip technology documents to share with a Chinese firm. This case, the first under Taiwan's National Security Act related to core semiconductor technologies, highlights continuing concerns about industrial espionage amid heightened geopolitical tensions.