Press "Enter" to skip to content

OSINT / CyberSec report 21.07.2026 00:10

1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer).

2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News).

3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote code execution (Reddit).

4. A new heap based buffer overflow vulnerability in 7-Zip tracked as CVE-2026-14266 allows attackers to execute code via crafted XZ archives (The Hacker News).

5. SonicWall Secure Mobile Access 1000 series VPN appliances were targeted by the threat actor UTA0533 using zero day exploits to gain root access (The Hacker News).

6. A critical heap buffer overflow vulnerability in NGINX tracked as CVE-2026-42533 allows remote unauthenticated attackers to crash worker processes or potentially execute code (The Hacker News).

7. Russian state sponsored group UAC-0145 is using ClickFix CAPTCHA tactics to trick Ukrainian users into installing data stealing malware (The Hacker News).

8. A supply chain attack dubbed SleeperGem is targeting developer machines by distributing malicious RubyGems packages (The Hacker News).

9. A Russian speaking threat actor identified as bandcampro utilized the Google Gemini CLI to manage a botnet infecting dental clinic computers (The Hacker News).

10. Threat actors are abusing the update mechanism of the ViPNet private networking suite to target Russian government agencies (BleepingComputer).

11. Over one million malicious emails have been identified using text salting techniques designed to bypass AI based security scanners (Reddit).

12. A proof of concept exploit for CVE-2026-49176 has been released targeting a local privilege escalation vulnerability in the Windows WalletService (Reddit).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *