📡 Tech & Security Digest — 2026-07-22
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Critical SharePoint RCE flaw exploited to steal machine keys — Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after…
- Critical wp2shell WordPress flaws exploited to install webshells — Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent w…
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang — The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecu…
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malwar…
- Estée Lauder discloses data breach via Oracle E-Business flaw — Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used f…
- Chick-fil-A discloses data breach after credential stuffing attacks — American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credentia…
- Windows LegacyHive zero-day flaw gets free, unofficial patches — Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Window…
Hacker News
- OpenAI and Hugging Face address security incident during model evaluation (1065 pts)
- Judge approves $1.5B Anthropic settlement for pirated books used to train Claude (323 pts)
- “Drawing” the Mona Lisa with GPT-5.6, Claude, Gemini, and Grok (185 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server…
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTow…
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access — Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka…
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning — Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (…
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution — Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.
In a post …
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with …
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series …
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft — Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.
Expel, whi…
- N-day is Becoming N-Hour. Patching Faster Won’t Save You. — Every patch is a confession.
The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly w…
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested…
The Verge
- OpenAI says it accidentally hacked Hugging Face with a new AI system — OpenAI says its AI models mistakenly breached open-source AI platform Hugging Face during internal testing. In a blog post on Tuesday, OpenAI writes t…