📰 DAILY THREAT BRIEFING
Thursday, July 23, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 23, 2026.

  1. Upbound says hack caused $13 million in fraudulent Acima leases
    — Bleeping Computer

    The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima l…
  2. Attackers Are Learning to Live Off the AI Toolchain
    — Dark Reading

    Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguish…
  3. South Korea discloses data breach impacting diplomats worldwide
    — Bleeping Computer

    South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal info…
  4. Fake Bahrain Alert App Deploys Android Surveillance Malware
    — Dark Reading

    A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile str…
  5. GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
    — The Hacker News

    Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop fro…
  6. Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
    — The Hacker News

    Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivilege…
  7. Rondo Meets Geoserver, (Wed, Jul 22nd)
    — SANS ISC

    This isn't a new attack, but something I saw "pop-up" in our logs this week:
  8. Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
    — Bleeping Computer

    Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange p…
  9. When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
    — Dark Reading

    Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
  10. Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
    — The Hacker News

    Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 31…
  11. ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. LG to Ban Residential Proxies from Smart TV Apps
    — Krebs on Security

    The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television i…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9714 in last 30 days).
Critical: 4 · High: 11 · Medium: 5 · Low: 0. View full dashboard →

  1. CVE-2026-16632
    — CVSS 7.3 (HIGH)

    A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipul…
  2. CVE-2026-16631
    — CVSS 5.3 (MEDIUM)

    A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command inje…
  3. CVE-2026-61246
    — CVSS 8.8 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  4. CVE-2026-60455
    — CVSS 8.8 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  5. CVE-2026-60439
    — CVSS 8.8 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  6. CVE-2026-60373
    — CVSS 8.8 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  7. CVE-2026-60372
    — CVSS 9.8 (CRITICAL)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  8. CVE-2026-60371
    — CVSS 8.0 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to expl…
  9. CVE-2026-60370
    — CVSS 7.5 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to expl…
  10. CVE-2026-60369
    — CVSS 9.9 (CRITICAL)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  11. CVE-2026-60368
    — CVSS 8.8 (HIGH)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  12. CVE-2026-60367
    — CVSS 9.8 (CRITICAL)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  13. CVE-2026-60366
    — CVSS 10.0 (CRITICAL)

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…
  14. CVE-2026-16630
    — CVSS 5.3 (MEDIUM)

    A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An …
  15. CVE-2026-16629
    — CVSS 5.3 (MEDIUM)

    A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argume…
  16. CVE-2026-16628
    — CVSS 5.3 (MEDIUM)

    A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins resul…
  17. CVE-2026-9737
    — CVSS 6.5 (MEDIUM)

    During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
  18. CVE-2026-64829
    — CVSS 7.4 (HIGH)

    Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow'…
  19. CVE-2026-14881
    — CVSS 7.8 (HIGH)

    When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for …
  20. CVE-2026-13078
    — CVSS 7.7 (HIGH)

    A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesyste…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 23, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com