July 23, 2026 Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy …
CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
July 23, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited …
Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities
July 23, 2026 Anthropic has released the Claude Security plugin in beta, bringing AI-powered vulnerability scanning directly into Claude Code for developers who want to catch high-severity flaws before they …
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
July 22, 2026 A new Linux vulnerability dubbed “RefluXFS” — a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected …
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
July 22, 2026 A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply …
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
July 22, 2026 ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked …
A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool
July 22, 2026 A recently disclosed vulnerability in AWS Kiro, an AI-powered Integrated Development Environment (IDE), reveals how a hidden line of text on a webpage can be exploited for …
Apple Releases Fixes for Hide My Email Flaw that Exposes Users’ Real Email Addresses
July 22, 2026 Apple has released a security fix addressing a critical flaw in its iCloud+ “Hide My Email” feature that could expose users’ real email addresses, undermining the core …
AI-Speed Attacks Are Forcing a Rethink of Incident Response
July 22, 2026 Byline: Nikola Petrovic Accelerating Attacks. Our Detection Processes Are Still Running on Human Time. In one of my previous roles, I regularly dealt with incident reports. Most of …
Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
July 22, 2026 Royal ransomware turned ordinary Windows compromises into enterprise-wide crises by pairing a phishing foothold with fast domain takeover. In incidents reviewed by responders, the operators used Qbot …
