This week’s bulletin exposes just how long dangerous flaws can hide in plain sight, with a 16-year-old Linux KVM escape bug and a 15-year-old kernel privilege escalation flaw both surfacing after more than a decade undetected. Enterprise infrastructure took a …
Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets
July 12, 2026 Apple has filed a federal lawsuit against OpenAI, accusing the ChatGPT maker of orchestrating a systematic campaign to steal confidential hardware designs, manufacturing processes, and supplier relationships through more than 400 former Apple employees now working at …
Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens
July 11, 2026 Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older than macOS Tahoe 26.4, …
New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents
July 11, 2026 A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such as .env files. The ASSET Research Group demonstrated that a …
Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts
July 11, 2026 Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, …
CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak
July 11, 2026 CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal, public GitHub account, triggering an internal incident response and a rare public …
Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds
July 11, 2026 A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CVE-2026-40639 (DSA-2026-197), stems from a broken …
281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted
July 11, 2026 A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens of these apps transfer data without encryption, leak user traffic …
Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat
July 10, 2026 Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a “credible external security threat” against the platform. The notice, sent directly …
One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers
July 10, 2026 Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message. The flaws, confirmed exploitable on OpenClaw 2026.6.1, expose a structural …
