July 14, 2026 The UK, joined by international cybersecurity partners, has issued an urgent warning about Russian state-backed hackers targeting poorly secured routers and network devices worldwide. The alert focuses …
SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory Corruption
July 14, 2026 SAP has released its July 2026 Security Patch Day updates, addressing a critical memory corruption vulnerability in the SAP NetWeaver Application Server ABAP. The most severe issue, …
Greenhat Announces Successful Delegation at Web Summit Vancouver 2026
July 14, 2026 Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing Canada–Korea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum …
150+ npm Packages Promises Wi-Fi Bypass Students Using Their Systems for DDoS Attack
July 14, 2026 Nearly 150 npm packages posing as school Wi-Fi bypass tools were used to turn visiting browsers into potential DDoS engines. The campaign presented itself as harmless tutoring-branded …
Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords
Microsoft is retiring phishable SMS and voice-based multifactor authentication in Microsoft Entra ID, replacing them with passkeys as the default sign-in method starting September 1, 2026. The move responds to …
US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations
July 14, 2026 The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has imposed sanctions on First VPN Service (1VPNS), a VPN provider accused of supplying infrastructure …
Critical ServiceNow Vulnerability Allows Remote Attackers to Execute Malicious Code
ServiceNow has disclosed and fixed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to execute code within affected ServiceNow environments. The flaw, tracked as CVE-2026-6875, …
Chrome Extension Used by 1.6 Million Users Silently Included Data Exfiltration Capabilities
July 14, 2026 A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, …
Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide
Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link …
New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials
July 13, 2026 CrashStealer, a native C++ macOS infostealer that disguises itself as Apple’s built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before …
