HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 21, 2026.
-
Estée Lauder discloses data breach via Oracle E-Business flaw
— Bleeping Computer
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the co… -
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
— Bleeping Computer
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install cus… -
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
— Bleeping Computer
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising … -
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
— Dark Reading
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against… -
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
— Dark Reading
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability … -
CISOs Feel the Heat Over AI Risk
— Dark Reading
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their po… -
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
— SANS ISC
Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced w… -
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
— The Hacker News
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intellig… -
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
— The Hacker News
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filena… -
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
— The Hacker News
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions… -
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
— SANS ISC
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long histor…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (8333 in last 30 days).
Critical: 1 · High: 10 · Medium: 9 · Low: 0. View full dashboard →
-
CVE-2026-63728
— CVSS 6.3 (MEDIUM)
Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging ⦠-
CVE-2026-55833
— CVSS 7.5 (HIGH)
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the ra⦠-
CVE-2026-55831
— CVSS 7.5 (HIGH)
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-b⦠-
CVE-2026-16327
— CVSS 7.3 (HIGH)
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The ⦠-
CVE-2026-64626
— CVSS 6.4 (MEDIUM)
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. A⦠-
CVE-2026-64625
— CVSS 9.8 (CRITICAL)
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS ⦠-
CVE-2026-64624
— CVSS 7.8 (HIGH)
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, ⦠-
CVE-2026-57852
— CVSS 5.6 (MEDIUM)
Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook ⦠-
CVE-2026-55550
— CVSS 7.1 (HIGH)
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion t⦠-
CVE-2026-55544
— CVSS 7.6 (HIGH)
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__⦠-
CVE-2026-51385
— CVSS 6.9 (MEDIUM)
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions. -
CVE-2026-47255
— CVSS 8.2 (HIGH)
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-ag⦠-
CVE-2026-47144
— CVSS 5.5 (MEDIUM)
Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose contents of files outside the repo⦠-
CVE-2026-47128
— CVSS 6.1 (MEDIUM)
nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to local Unix domain sockets (concrete and abstract). This allows an⦠-
CVE-2026-44510
— CVSS 6.5 (MEDIUM)
Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver-side out-of-bounds array read in rsync's recv_files() lets a malicious rsy⦠-
CVE-2026-16324
— CVSS 7.3 (HIGH)
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unr⦠-
CVE-2026-12900
— CVSS 6.4 (MEDIUM)
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insu⦠-
CVE-2026-58624
— CVSS 5.4 (MEDIUM)
Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to â¦
-
CVE-2026-56624
— CVSS 7.3 (HIGH)
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.Server-side OpenSSH user certificate validation during user authentication iâ¦
-
CVE-2026-56623
— CVSS 7.1 (HIGH)
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH.A git server implemented with Apache MINA SSHD component sshd-git and runningâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 21, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com