2026-07-19
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilitiesCVE-2026-42533
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 released patches for a critical nginx heap buffer overflow vulnerability (CVE-2026-42533) that allows unauthenticated remote attackers to crash worker processes with specially crafted HTTP requests. The flaw was patched on July 15, 2026 in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Exploitation can cause denial of service by restarting or crashing workers.
Why it matters: Organizations running nginx versions before 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 face immediate denial of service risk from unauthenticated attackers and should prioritize patching to restore stability.
- ot ics
Scans for Hikvision Intelligent Security API
Internet-wide scans targeting Hikvision cameras are now probing the Intelligent Security application programming interface (API), a REST-based endpoint that can fully control camera settings and manage devices. The ISAPI endpoint /ISAPI/System/status allows reconnaissance and potential password brute-forcing, and the API's encryption provides minimal security when basic authentication is used over HTTP.
Why it matters: Organizations with Hikvision cameras exposed to the internet face active reconnaissance targeting the API endpoint, requiring immediate verification that cameras are not internet-accessible and operate over HTTPS with strong credentials to prevent unauthorized access and camera compromise.
- threat intel
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is exploiting the update mechanism of ViPNet, a private networking product suite, to target Russian organizations and government agencies. The attack leverages the software's legitimate update channel to deliver malicious payloads. This represents a supply chain vector that affects trust in established security software.
Why it matters: Russian government agencies and organizations relying on ViPNet for secure communications face direct compromise through trusted update channels; practitioners should verify the integrity of recent ViPNet updates and monitor for anomalous behavior from the software.
- threat intel
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
UAC-0145, a sub-cluster of the Russian state-sponsored Sandworm group, has been conducting a campaign against Ukrainian targets using ClickFix CAPTCHAs to lure victims into installing data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) detected and attributed the activity, which exploits a social engineering technique to trick users into compromising their own devices.
Why it matters: Ukrainian organizations and individuals face targeted infection campaigns from a Russian state actor; practitioners should educate users on ClickFix threats and enforce controls to block unauthorized malware installation.
- breaches incidents
Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches
Abbott Laboratories is investigating two separate cyber incidents: one affecting its Cancer Diagnostics business and another targeting its LabCentral portal. Both incidents occurred within days of each other, with threat actors ShinyHunters and ShadowByt3$ claiming responsibility for breaches. The company disclosed unauthorized access to limited systems but has not yet provided comprehensive details on the scope or nature of data compromised.
Why it matters: Healthcare organizations and patients using Abbott's diagnostic services and lab portals face potential exposure of sensitive health information; practitioners should monitor Abbott's official advisories and assess whether their organization uses affected systems.
- vulnerabilities
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously unknown threat actor tracked as UTA0533 exploited SonicWall Secure Mobile Access (SMA) 1000 series virtual private network (VPN) appliances as zero-day vulnerabilities before public disclosure on June 22, 2026. Volexity discovered the activity during incident response work and attributed it to root access attempts on the affected devices.
Why it matters: Organizations running SonicWall SMA 1000 series VPN appliances need to determine if they were compromised before the June 22, 2026 disclosure and apply patches immediately, as an active threat actor had working exploits.
- vulnerabilities
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
A WordPress 7.0.2 security release addresses one critical and one high severity vulnerability requiring immediate patching. The week also covered an open-source deep research agent that runs language models against live cloud accounts to identify security gaps, alongside discussion of fake OAuth IDs that can bypass sign-in logging mechanisms.
Why it matters: WordPress administrators must patch immediately to close critical and high severity flaws; organizations using LLM-based security agents need to understand credential and access risks; teams relying on OAuth for authentication and audit trails should assess exposure to spoofed identity attacks.