New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry …

Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows an authenticated local attacker with low privileges to gain administrator-level access on affected systems. CVE-2026-56155 …

Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 Notepad++ v8.9.7 has been released with critical security fixes addressing multiple vulnerabilities, including a high-risk PowerShell command injection flaw that could enable arbitrary code execution during installation. The update resolves five distinct issues spanning path traversal, buffer …

Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 15, 2026 A newly disclosed Windows BitLocker 0‑day vulnerability, tracked as CVE-2026-50661, exposes encrypted devices to physical attacks that can completely undermine Microsoft’s disk encryption guarantees. The flaw, classified as a security feature bypass, stems from a protection mechanism …

Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Tel Aviv, Israel, July 14th, 2026, CyberNewswire Cybersecurity start-up Tego AI reveals that the new Anthropic’s native slack integration, Claude Tag, can be triggered by non-intentional Slack content and drive unauthorized actions across enterprise systems. Tego AI, …

Microsoft Patches a Record 570 Security Flaws

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft …

Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. This massive patch follows the recent Microsoft update on artificial intelligence …

Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Anthropic’s Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim’s Gmail, Google Docs, and Calendar data using just six lines of JavaScript, even after eight subsequent releases. Manifold researchers first …

FortiSandbox Vulnerability Exposes VNC Server to Unauthenticated Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could let unauthenticated attackers gain access to the VNC server of virtual machines used for malware scanning. Tracked as CVE-2026-59835, the flaw is classified as an Exposure of …

AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 14, 2026 A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm …