July 22, 2026 Oracle has released its July 2026 Critical Patch Update (CPU), shipping 1,449 security patches that collectively remediate more than 1,200 vulnerabilities across databases, middleware, cloud services, and …
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
July 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to …
Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
July 22, 2026 Zimbra fixed a critical Zimbra Collaboration Suite (ZCS) command injection flaw in version 10.1.20 that could allow attackers to abuse the SNMP service and execute arbitrary commands …
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims
July 22, 2026 The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target …
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
July 22, 2026 An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects …
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
July 22, 2026 A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding …
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
July 22, 2026 Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed …
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
July 22, 2026 Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in …
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
July 22, 2026 A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights …
Authorities Shut Down Phishing Empire Launching 15,000 Attacks Every Month
July 22, 2026 Authorities dismantled Kratos, a major phishing-as-a-service operation behind around 15,000 monthly phishing campaigns, shutting down a global infrastructure used for large-scale credential theft. The operation involved collaboration …
