📡 Tech & Security Digest — 2026-07-17
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- CISA orders feds to patch actively exploited Oracle flaw by Saturday — CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Busi…
- Russian hackers trojanize WebEx, Zoom apps to push Starland malware — A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a …
- Google Gemini CLI abused as a hacking agent, malware botnet operator — A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale bot…
- CISA urges immediate action on actively exploited Fortinet flaws — CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detecti…
Hacker News
- $100 AI Music Video: Claude Fable 5 vs. GPT-5.6 Sol (235 pts)
- How to Train a Gen AI Kick Drum Model on Your Old Linux Desktop with 6GB VRAM (122 pts)
- Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps (39 pts)
- EEG shows brain can simultaneous encode two speech streams (50 pts)
- LM Studio Bionic: the AI agent for open models (230 pts)
- NotebookLM is now Gemini Notebook (298 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release cover…
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server…
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday — Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been describe…
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover — Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.
The vuln…
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data — SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver A…
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws — Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities a…
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensio…
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which …
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More — Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is tha…
- New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands — Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lure…