Microsoft Patches a Record 570 Security Flaws

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft …

Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. This massive patch follows the recent Microsoft update on artificial intelligence …

Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Anthropic’s Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim’s Gmail, Google Docs, and Calendar data using just six lines of JavaScript, even after eight subsequent releases. Manifold researchers first …

FortiSandbox Vulnerability Exposes VNC Server to Unauthenticated Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could let unauthenticated attackers gain access to the VNC server of virtual machines used for malware scanning. Tracked as CVE-2026-59835, the flaw is classified as an Exposure of …

AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm …

Miasma Turns Trusted npm Packages Into Persistent Backdoors for Developer Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Miasma has returned through software packages that many developers would normally trust. Four AsyncAPI packages on npm were altered to deliver a Miasma v3 payload, creating a route for long-term remote access. The campaign does not depend …

xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A wire-level analysis of xAI’s Grok Build CLI revealed that version 0.2.93 transmitted unredacted file contents, including secrets from .env files, and uploaded full Git repositories along with their commit history to cloud storage These findings are …

VMware Avi Load Balancer Vulnerabilities Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Broadcom-owned VMware has disclosed multiple security flaws in its Avi Load Balancer platform (formerly NSX Advanced Load Balancer) that let attackers bypass authentication controls and gain unauthorized database access through crafted SQL queries. The most severe of …

Pro-Iran Hacktivists Use Telegram-Coordinated DDoS and Hack-and-Leak Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Pro-Iran hacktivist networks are turning Telegram channels into hubs for cyber retaliation. Their campaigns combine website-disrupting DDoS floods with hack-and-leak claims, using public posts to recruit supporters, circulate target lists, and magnify disruption. The activity has created …

New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT hash and NTLM password hashes for every account in the …