Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 Royal ransomware turned ordinary Windows compromises into enterprise-wide crises by pairing a phishing foothold with fast domain takeover. In incidents reviewed by responders, the operators used Qbot …

Russian Intelligence Hijacks IP Cameras to Monitor Weapons Deliveries to Ukraine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 Russian intelligence services have been accused of turning everyday internet-connected cameras into surveillance tools for tracking weapons deliveries to Ukraine. The campaign shows how a device installed …

A Single Extra “t” in a NuGet Package Allow Attackers to Manipulate Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 A malicious NuGet package used a single extra letter to hide in plain sight, turning a familiar software dependency into a betting-fraud tool. The package, Newtonsoftt.Json.Net, copied the …

New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating …

Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 Oracle has released its July 2026 Critical Patch Update (CPU), shipping 1,449 security patches that collectively remediate more than 1,200 vulnerabilities across databases, middleware, cloud services, and …

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to …

Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 Zimbra fixed a critical Zimbra Collaboration Suite (ZCS) command injection flaw in version 10.1.20 that could allow attackers to abuse the SNMP service and execute arbitrary commands …

FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target …

Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 22, 2026 An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects …