📰 DAILY THREAT BRIEFING
Wednesday, July 22, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 22, 2026.

  1. Police dismantle Kratos phishing platform, arrest developer
    — Bleeping Computer

    Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global re…
  2. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
    — Bleeping Computer

    A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumula…
  3. Ransomware Is Accelerating, But It's Not Because of AI
    — Dark Reading

    Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended …
  4. Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
    — Dark Reading

    The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for…
  5. Critical SharePoint RCE flaw exploited to steal machine keys
    — Bleeping Computer

    Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access …
  6. Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
    — The Hacker News

    Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively…
  7. Hacker Turns AI Jailbreaks Into Offensive Attack Platform
    — Dark Reading

    A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.
  8. AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
    — The Hacker News

    Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code o…
  9. Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
    — The Hacker News

    Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.…
  10. Captive Portal Detection, (Tue, Jul 21st)
    — SANS ISC

    Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" list current…
  11. ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
    — SANS ISC

    Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced w…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9733 in last 30 days).
Critical: 0 · High: 5 · Medium: 14 · Low: 1. View full dashboard →

  1. CVE-2026-63263
    — CVSS 6.5 (MEDIUM)

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that c…
  2. CVE-2026-63262
    — CVSS 4.3 (MEDIUM)

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
  3. CVE-2026-16489
    — CVSS 5.3 (MEDIUM)

    A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command in…
  4. CVE-2026-16488
    — CVSS 5.0 (MEDIUM)

    A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation c…
  5. CVE-2026-63261
    — CVSS 6.5 (MEDIUM)

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learn…
  6. CVE-2026-63260
    — CVSS 6.5 (MEDIUM)

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in K…
  7. CVE-2026-63259
    — CVSS 4.3 (MEDIUM)

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not aut…
  8. CVE-2026-63145
    — CVSS 4.3 (MEDIUM)

    Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1).

    A vulnerability exi…

  9. CVE-2026-63144
    — CVSS 6.5 (MEDIUM)

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a re…
  10. CVE-2026-63143
    — CVSS 4.3 (MEDIUM)

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana spac…
  11. CVE-2026-63142
    — CVSS 5.0 (MEDIUM)

    Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the report…
  12. CVE-2026-56820
    — CVSS 7.4 (HIGH)

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` i…
  13. CVE-2026-56819
    — CVSS 7.5 (HIGH)

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one dir…
  14. CVE-2026-16517
    — CVSS 2.9 (LOW)

    A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to…
  15. CVE-2026-16486
    — CVSS 4.3 (MEDIUM)

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The at…
  16. CVE-2026-16485
    — CVSS 4.3 (MEDIUM)

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross si…
  17. CVE-2026-65319
    — CVSS 7.5 (HIGH)

    Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, wh…
  18. CVE-2026-65318
    — CVSS 8.6 (HIGH)

    Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attac…
  19. CVE-2026-65317
    — CVSS 8.6 (HIGH)

    Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP …
  20. CVE-2026-65316
    — CVSS 6.5 (MEDIUM)

    XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequ…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 22, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com