July 15, 2026 New research uncovered 11 malicious NuGet packages disguised as game cheats, bots, and management panels for popular online titles. The campaign targets gaming communities playing titles such …
New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry
July 15, 2026 A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another …
Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild
July 15, 2026 Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows an authenticated local attacker with …
Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks
July 15, 2026 Notepad++ v8.9.7 has been released with critical security fixes addressing multiple vulnerabilities, including a high-risk PowerShell command injection flaw that could enable arbitrary code execution during installation. …
Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
July 15, 2026 A newly disclosed Windows BitLocker 0‑day vulnerability, tracked as CVE-2026-50661, exposes encrypted devices to physical attacks that can completely undermine Microsoft’s disk encryption guarantees. The flaw, classified …
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
July 14, 2026 Tel Aviv, Israel, July 14th, 2026, CyberNewswire Cybersecurity start-up Tego AI reveals that the new Anthropic’s native slack integration, Claude Tag, can be triggered by non-intentional Slack …
Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. This …
Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data
July 14, 2026 Anthropic’s Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim’s Gmail, Google Docs, and Calendar data using just six lines …
FortiSandbox Vulnerability Exposes VNC Server to Unauthenticated Attackers
July 14, 2026 Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could let unauthenticated attackers gain access to the VNC server of virtual machines used for malware scanning. Tracked …
AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions
July 14, 2026 A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, …
