July 24, 2026 Russian state-backed hackers, identified as LAUNDRY BEAR, are exploiting a zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) to stealthily extract sensitive information, including emails, from Western …
Malicious RubyGems Turn Developer Machines Into Monero Miners and Spread Through SSH
July 24, 2026 A malicious RubyGems campaign has turned seemingly useful developer packages into tools for hidden cryptocurrency mining. The poisoned packages can consume a machine’s computing power, slow down …
Microsoft 365 Services Outage Impacted Teams, Copilot, Purview and Other Services
July 24, 2026 A Microsoft 365 outage disrupted access to several widely used enterprise services, including Microsoft Teams, SharePoint Online, OneDrive, Copilot Chat, Microsoft Purview, and Power BI. The incident …
Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records
July 24, 2026 A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. The database was advertised on a cybercrime forum, …
Hackers Abuse Notepad++ Plugins to Compromise Your System Silently
A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group’s tactics …
Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel
July 23, 2026 Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a …
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
July 23, 2026 A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents …
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, …
Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks
July 23, 2026 A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked …
Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability
July 23, 2026 Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The …
