HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 20, 2026.
-
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
— The Hacker News
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker pro… -
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
— SANS ISC
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long histor… -
Hackers abuse ViPNet software to target Russian govt agencies
— Bleeping Computer
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, in… -
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
— The Hacker News
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting… -
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
— The Hacker News
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 10… -
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
— Bleeping Computer
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious cod… -
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
— Bleeping Computer
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imp… -
Inc Ransomware Exploits SonicWall SMA Zero-Days
— Dark Reading
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. -
The Real AI Threat Is Blind Trust
— Dark Reading
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. -
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
— Dark Reading
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's bein… -
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
— Unit 42
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent … -
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (8105 in last 30 days).
Critical: 1 · High: 2 · Medium: 1 · Low: 0. View full dashboard →
-
CVE-2026-45138
— CVSS 5.4 (MEDIUM)
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), ⦠-
CVE-2026-44359
— CVSS 10.0 (CRITICAL)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the att⦠-
CVE-2026-42566
— CVSS 7.5 (HIGH)
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE wh⦠-
CVE-2026-12484
— CVSS 7.8 (HIGH)
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `toâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 20, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com