📰 DAILY THREAT BRIEFING
Friday, July 17, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 17, 2026.

  1. AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
    — Unit 42

    Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, …
  2. New ClickLock macOS malware traps users into revealing login password
    — Bleeping Computer

    A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login p…
  3. Coca-Cola says Fairlife ransomware attack halts US dairy production
    — Bleeping Computer

    The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily…
  4. Agentic AI Is Untamable: Ask the Right Security Questions
    — Dark Reading

    Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.
  5. 1M+ Emails Use Hidden Text to Dupe AI Security Filters
    — Dark Reading

    Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inb…
  6. Claude Chrome extension flaw lets malicious extensions trigger AI actions
    — Bleeping Computer

    A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating u…
  7. Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
    — The Hacker News

    Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for…
  8. ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
    — The Hacker News

    A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. …
  9. n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
    — The Hacker News

    n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one ext…
  10. Police Disrupt a €140M Cyber Fraud Ring in Spain
    — Dark Reading

    Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.
  11. ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
    — Unit 42

    Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (8352 in last 30 days).
Critical: 2 · High: 11 · Medium: 7 · Low: 0. View full dashboard →

  1. CVE-2026-54340
    — CVSS 7.5 (HIGH)

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalli…
  2. CVE-2026-39359
    — CVSS 7.5 (HIGH)

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd)…
  3. CVE-2026-34150
    — CVSS 7.5 (HIGH)

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attac…
  4. CVE-2026-33754
    — CVSS 6.5 (MEDIUM)

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser b…
  5. CVE-2026-33434
    — CVSS 4.3 (MEDIUM)

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoin…
  6. CVE-2026-44453
    — CVSS 7.5 (HIGH)

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o bu…
  7. CVE-2026-44452
    — CVSS 5.9 (MEDIUM)

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over …
  8. CVE-2026-44436
    — CVSS 7.5 (HIGH)

    Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a Denial of Service attack through connection state corruption. In QU…
  9. CVE-2026-44435
    — CVSS 7.5 (HIGH)

    Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received ove…
  10. CVE-2026-44434
    — CVSS 5.3 (MEDIUM)

    Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. T…
  11. CVE-2026-44433
    — CVSS 5.3 (MEDIUM)

    Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset be…
  12. CVE-2026-43978
    — CVSS 8.1 (HIGH)

    wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the tra…
  13. CVE-2026-43977
    — CVSS 7.5 (HIGH)

    wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /l…
  14. CVE-2026-62826
    — CVSS 4.6 (MEDIUM)

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
  15. CVE-2026-59117
    — CVSS 7.5 (HIGH)

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
  16. CVE-2026-58643
    — CVSS 6.1 (MEDIUM)

    Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
  17. CVE-2026-58598
    — CVSS 7.0 (HIGH)

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
  18. CVE-2026-53412
    — CVSS 9.8 (CRITICAL)

    Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
  19. CVE-2026-53411
    — CVSS 7.8 (HIGH)

    A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
  20. CVE-2026-44180
    — CVSS 9.8 (CRITICAL)

    Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohibited UID and GID fe…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 17, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com