Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. This …
Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data
July 14, 2026 Anthropic’s Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim’s Gmail, Google Docs, and Calendar data using just six lines …
FortiSandbox Vulnerability Exposes VNC Server to Unauthenticated Attackers
July 14, 2026 Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could let unauthenticated attackers gain access to the VNC server of virtual machines used for malware scanning. Tracked …
AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions
July 14, 2026 A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, …
Miasma Turns Trusted npm Packages Into Persistent Backdoors for Developer Machines
July 14, 2026 Miasma has returned through software packages that many developers would normally trust. Four AsyncAPI packages on npm were altered to deliver a Miasma v3 payload, creating a …
xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage
July 14, 2026 A wire-level analysis of xAI’s Grok Build CLI revealed that version 0.2.93 transmitted unredacted file contents, including secrets from .env files, and uploaded full Git repositories along …
VMware Avi Load Balancer Vulnerabilities Let Attackers Bypass Authentication
July 14, 2026 Broadcom-owned VMware has disclosed multiple security flaws in its Avi Load Balancer platform (formerly NSX Advanced Load Balancer) that let attackers bypass authentication controls and gain unauthorized …
Pro-Iran Hacktivists Use Telegram-Coordinated DDoS and Hack-and-Leak Attacks
July 14, 2026 Pro-Iran hacktivist networks are turning Telegram channels into hubs for cyber retaliation. Their campaigns combine website-disrupting DDoS floods with hack-and-leak claims, using public posts to recruit supporters, …
New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol
July 14, 2026 A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT …
CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks
July 14, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS …
