July 22, 2026 An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects …
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
July 22, 2026 A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding …
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
July 22, 2026 Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed …
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
July 22, 2026 Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in …
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
July 22, 2026 A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights …
Authorities Shut Down Phishing Empire Launching 15,000 Attacks Every Month
July 22, 2026 Authorities dismantled Kratos, a major phishing-as-a-service operation behind around 15,000 monthly phishing campaigns, shutting down a global infrastructure used for large-scale credential theft. The operation involved collaboration …
Yubico Released YubiKey 5.8 With Secure Enterprise Workflows and AI-driven Approvals
July 22, 2026 Yubico has announced the release of YubiKey 5.8, a firmware update that enhances the functionality of hardware-backed passkeys beyond secure login authentication, extending into verified authorization workflows. …
GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews. The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, …
Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild
July 22, 2026 A critical ServiceNow vulnerability, tracked as CVE-2026-6875, is being actively exploited to allow unauthenticated attackers to escape the script sandbox and execute code on affected systems. The …
Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks
July 22, 2026 Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181/.182 …
