July 20, 2026 Microsoft has released the out-of-band update KB5121767 for Windows 11 to resolve a system performance and compatibility issue affecting a limited number of Dell devices. The update …
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
July 20, 2026 Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put …
Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability
July 20, 2026 ServiceNow has released security updates for a critical vulnerability in its AI platform after researchers published a proof of concept demonstrating pre-authentication remote code execution. The flaw, …
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
July 20, 2026 GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. …
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
July 20, 2026 Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The …
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
July 20, 2026 North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation …
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
July 20, 2026 A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security …
Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
July 19, 2026 This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch …
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
July 19, 2026 A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since …
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
July 18, 2026 Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using …
