July 21, 2026 A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool …
Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware
July 21, 2026 A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a …
Healthcare Giant Abbott Investigating Cyber Incident Following ShinyHunters Claims
Abbott has confirmed that it is investigating a cyber incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. This follows claims associated …
SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
July 21, 2026 Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the …
Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
July 21, 2026 Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification …
One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
July 21, 2026 A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than …
Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection
July 21, 2026 The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, …
Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
July 21, 2026 Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches …
Hackers Could Turn AI Training Jobs Into Weapons Against the Power Grid
July 21, 2026 A new research threat called Bit2Watt shows how AI training jobs could be abused to disrupt the power systems that support data centers. Rather than installing malware …
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every …

