📡 Tech & Security Digest — 2026-07-15
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now — SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks…
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days — Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabiliti…
- Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown — Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers las…
- LastPass, Bitwarden users targeted with fake security alerts — LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. […]…
- US sanctions VPN, malware providers for enabling ransomware attacks — The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks again…
Hacker News
- Guardian Angels: LLM Personalization for Productivity and Security (83 pts)
- Cursor 0day: When Full Disclosure Becomes the Only Protection Left (336 pts)
- Microsoft has released software updates to plug at least 570 security holes (106 pts)
- I tricked Claude into leaking your deepest, darkest secrets (108 pts)
- Jurassic Park computers in excruciating detail (329 pts)
- TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access (129 pts)
Krebs on Security
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release cover…
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges — Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.
Th…
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data — SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver A…
- Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws — Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully expl…
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensio…
- Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how s…
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which …
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More — Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is tha…
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic — The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
Chinese cy…
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access — A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to e…