HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 24, 2026.
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
— Dark Reading
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the … -
New Dolphin X malware uses AI to rank high-value targets
— Bleeping Computer
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals… -
Australian energy provider Origin says data breach exposes client data
— Bleeping Computer
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally … -
Fake Claude app promoted by Bing ads pushes SectopRAT malware
— Bleeping Computer
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to… -
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
— The Hacker News
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The… -
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
— The Hacker News
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app beca… -
Russian Global Webmail Espionage
— Unit 42
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post… -
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
— SANS ISC
Two disclosures, five days apart, described the same intrusion from opposite ends â one from the victim, one from the party tha… -
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
— The Hacker News
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of … -
Agentic AI Challenges Progress in Confidential Computing
— Dark Reading
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Ex… -
Brazilian Banking Trojan Actively Spreading in Portugal
— Dark Reading
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. -
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9828 in last 30 days).
Critical: 4 · High: 10 · Medium: 6 · Low: 0. View full dashboard →
-
CVE-2026-50044
— CVSS 6.8 (MEDIUM)
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack. -
CVE-2026-44955
— CVSS 5.3 (MEDIUM)
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users. -
CVE-2026-42933
— CVSS 10.0 (CRITICAL)
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation. -
CVE-2026-40430
— CVSS 7.5 (HIGH)
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. -
CVE-2026-28698
— CVSS 8.6 (HIGH)
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem. -
CVE-2026-16767
— CVSS 6.5 (MEDIUM)
A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName resu⦠-
CVE-2026-65694
— CVSS 7.5 (HIGH)
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the p⦠-
CVE-2026-65604
— CVSS 8.2 (HIGH)
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skippe⦠-
CVE-2026-63732
— CVSS 9.9 (CRITICAL)
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, an⦠-
CVE-2026-63313
— CVSS 7.7 (HIGH)
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provid⦠-
CVE-2026-16765
— CVSS 7.3 (HIGH)
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lea⦠-
CVE-2026-16764
— CVSS 6.3 (MEDIUM)
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads ⦠-
CVE-2026-16763
— CVSS 5.3 (MEDIUM)
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argumen⦠-
CVE-2025-71389
— CVSS 10.0 (CRITICAL)
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled i⦠-
CVE-2024-58355
— CVSS 8.9 (HIGH)
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dan⦠-
CVE-2024-58354
— CVSS 9.9 (CRITICAL)
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's defaul⦠-
CVE-2024-58353
— CVSS 8.9 (HIGH)
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendere⦠-
CVE-2026-50103
— CVSS 6.5 (MEDIUM)
A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value. -
CVE-2026-50039
— CVSS 7.5 (HIGH)
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request. -
CVE-2026-50032
— CVSS 7.5 (HIGH)
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 24, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com