📡 Tech & Security Digest — 2026-07-20
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- New Windows LegacyHive zero-day gives hackers admin privileges — A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate…
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now — Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative th…
- Abbott probes two cyber incidents amid extortion claims — Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences syste…
- CISA urges immediate action on actively exploited Fortinet flaws — CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detecti…
Hacker News
- Claude Code uses Bun written in Rust now (504 pts)
- OpenAI reduces Codex Model Context Size from 372k to 272k (340 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release cover…
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server…
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday — Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been describe…
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover — Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.
The vuln…
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data — SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver A…
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with …
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series …
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft — Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.
Expel, whi…
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws — Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities a…
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested…