📡 Tech & Security Digest — 2026-07-21
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malwar…
- Critical ServiceNow code execution flaw now exploited in attacks — Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defus…
- Estée Lauder discloses data breach via Oracle E-Business flaw — Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used f…
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes — Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. M…
- Windows LegacyHive zero-day flaw gets free, unofficial patches — Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Window…
- JadePuffer agentic attacks now target AI model data with ransomware — The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, v…
- Hugging Face warns an autonomous AI agent hacked its network — The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its pr…
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now — Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative th…
Hacker News
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release cover…
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server…
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday — Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been describe…
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover — Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover.
The vuln…
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data — SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver A…
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution — Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.
In a post …
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with …
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series …
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft — Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.
Expel, whi…
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws — Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities a…