<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Adobe Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Adobe.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>End-to-End Encryption and “Going Dark”</title><link>https://schneier.com/blog/archives/2026/07/end-to-end-encryption-and-going-dark.html</link><guid isPermaLink="false">cst-3097</guid><description>A new academic paper analyzes the third round of the 'Going Dark' debate, tracing encryption policy from the 1990s Crypto Wars through current end-to-end encryption (E2EE) controversies. The authors identify five distinct E2EE technical scenarios and demonstrate that E2EE is embedded throughout modern infrastructure including Transport Layer Security, Secure Shell, Virtual Private Networks, and Zero Trust Architecture, arguing that broad restrictions would harm cybersecurity and government operations.</description><pubDate>Thu, 23 Jul 2026 11:03:50 GMT</pubDate></item><item><title>Adobe Chrome extension flaw let sites access private WhatsApp chats</title><link>https://bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats</link><guid isPermaLink="false">cst-2996</guid><description>A vulnerability in the Adobe Acrobat extension for Chrome allowed unauthorized access to WhatsApp Web conversations and data without requiring authentication. The flaw exposed private messages and information that should have been protected, affecting users who had both the extension and WhatsApp Web open in their browser.</description><pubDate>Wed, 22 Jul 2026 13:22:20 GMT</pubDate></item><item><title>Oracle July 2026 Critical Patch Update Addresses 1235 CVEs</title><link>https://tenable.com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves</link><guid isPermaLink="false">cst-2966</guid><description>Oracle released its July 2026 Critical Patch Update on July 21, addressing 1235 unique CVEs across 1449 patches spanning 32 product families. The release included 261 critical patches (18% of all patches), with Oracle E-Business Suite and Fusion Middleware receiving the largest share of fixes. The update covers vulnerabilities across multiple severity levels, with 219 patches in Fusion Middleware exploitable remotely without authentication.</description><pubDate>Tue, 21 Jul 2026 21:07:46 GMT</pubDate></item><item><title>Director of Commerce AI standards office out after three months</title><link>https://cyberscoop.com/director-of-commerce-ai-standards-office-out-after-three-months</link><guid isPermaLink="false">cst-2861</guid><description>Chris Fall has stepped down as director of the Center for AI Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) after three months, with NIST Director Arvind Raman assuming the acting director role. CAISI has become a key federal hub for testing frontier AI models from companies like OpenAI and Anthropic to assess cybersecurity and national security risks, including potential offensive hacking capabilities and assistance with weapons development. Fall's departure comes as the White House has elevated CAISI's work as a critical mechanism for evaluating whether new AI models represent a meaningful advance in dangerous capabilities.</description><pubDate>Mon, 20 Jul 2026 18:10:03 GMT</pubDate></item><item><title>New North Korean campaign uses fake coding interviews to steal developer credentials</title><link>https://elastic.co/security-labs/contagious-interview-malware-svg-steganography</link><guid isPermaLink="false">cst-2774</guid><description>Elastic Security Labs discovered a North Korean-aligned campaign, tracked as REF9403, that uses fake job postings and coding challenges to distribute malware hidden in SVG image files via steganography. The trojanized code repositories appear functional but install a four-stage payload including credential and wallet stealers, file exfiltration, a Socket.IO-based remote access trojan, and clipboard stealing capabilities. The campaign demonstrates how threat actors target developers to establish initial access for downstream supply chain attacks.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Risk of Exposed Cloud Functions and How to Harden</title><link>https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden</link><guid isPermaLink="false">cst-2607</guid><description>Mandiant security assessments identify publicly exposed serverless applications and functions lacking authentication that frequently contain vulnerabilities in custom code or third-party packages. Successful exploitation of application-level flaws like local file inclusion or command injection can grant attackers remote code execution and container-level access, which may lead to lateral movement and cloud environment compromise. The article describes attack scenarios and hardening strategies for securing serverless deployments that must remain publicly accessible.</description><pubDate>Wed, 15 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws</title><link>https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html</link><guid isPermaLink="false">cst-2594</guid><description>Mozilla released Firefox updates to patch two critical vulnerabilities in the JavaScript/WebAssembly and DOM/Navigation components with known public exploit code. Chrome, Adobe, and VMware also issued updates for multiple critical security flaws, though details on those vendors' patches are not provided in this incomplete summary.</description><pubDate>Wed, 15 Jul 2026 13:18:53 GMT</pubDate></item><item><title>Microsoft releases Windows 10 KB5099539 extended security update</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update</link><guid isPermaLink="false">cst-2513</guid><description>Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.</description><pubDate>Tue, 14 Jul 2026 18:49:28 GMT</pubDate></item><item><title>Adobe Patches Critical ColdFusion Vulnerabilities</title><link>https://securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities</link><guid isPermaLink="false">cst-2519</guid><description>Adobe released patches for critical vulnerabilities in ColdFusion that could enable remote code execution and privilege escalation. The flaws pose significant risk to organizations running vulnerable versions of the application server.</description><pubDate>Tue, 14 Jul 2026 17:06:35 GMT</pubDate></item><item><title>SAP warns of critical flaws in NetWeaver and Commerce Cloud</title><link>https://bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud</link><guid isPermaLink="false">cst-2474</guid><description>The vendor released security updates addressing 16 vulnerabilities across multiple products in July 2026, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The updates cover significant exposure in SAP's enterprise middleware and cloud commerce platforms.</description><pubDate>Tue, 14 Jul 2026 11:42:21 GMT</pubDate></item><item><title>In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops</title><link>https://securityweek.com/in-other-news-dhs-database-hacked-adobe-boosts-patch-cadence-canada-disrupts-ransomware-ops</link><guid isPermaLink="false">cst-2335</guid><description>This news roundup mentions several security stories: a breach of a Department of Homeland Security database, Adobe increasing its patch release frequency, and Canadian authorities disrupting ransomware operations. The article also references a lawsuit between Abnormal AI and Anthropic, a data breach affecting 7 million AssuranceAmerica customers, and the NSA reactivating its Tailored Access Operations unit.</description><pubDate>Fri, 10 Jul 2026 15:01:19 GMT</pubDate></item><item><title>Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail</title><link>https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced</link><guid isPermaLink="false">cst-2283</guid><description>Angelo John Martino III, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with BlackCat affiliates to extort $75.3 million from five U.S. companies he was hired to help during ransomware incidents. Martino shared confidential negotiating positions and insurance policy limits with his co-conspirators to maximize ransom demands, effectively playing both sides of negotiations between April and September 2023. His co-conspirators, including fellow DigitalMint negotiator Kevin Tyler Martin and Sygnia incident response manager Ryan Clifford Goldberg, received four-year sentences for their roles in deploying BlackCat ransomware against additional victims.</description><pubDate>Fri, 10 Jul 2026 00:16:13 GMT</pubDate></item><item><title>Srsly Risky Biz: Supreme Court Undermines Section 702</title><link>https://risky.biz/ssupreme-court-undermines-section-702</link><guid isPermaLink="false">cst-2233</guid><description>A recent US Supreme Court decision may disrupt Section 702 intelligence collection involving data from Europe. Section 702 permits the US government to compel communication service providers to assist in collecting intelligence on non-US persons, and this collection has depended on data sharing agreements that enable legal personal data transfers from the EU to the US. The ruling creates legal uncertainty for the transatlantic intelligence framework that has underpinned both foreign intelligence operations and international commerce.</description><pubDate>Thu, 09 Jul 2026 08:48:42 GMT</pubDate></item><item><title>CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws</title><link>https://securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws</link><guid isPermaLink="false">cst-2155</guid><description>CISA has added four newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: critical flaws in Adobe ColdFusion and Langflow, plus two Joomla extension vulnerabilities. Federal agencies have until July 10 to apply patches for these active threats.</description><pubDate>Wed, 08 Jul 2026 10:45:25 GMT</pubDate></item><item><title>Phishing poses as big-brand job interview to steal Google accounts</title><link>https://bleepingcomputer.com/news/security/phishing-poses-as-big-brand-job-interview-to-steal-google-accounts</link><guid isPermaLink="false">cst-481</guid><description>A phishing campaign is impersonating over 30 major brands including Adobe, Netflix, Coca-Cola, and OpenAI by posing as fake job interviews targeting marketing professionals to harvest Google account credentials. Attackers use the trusted brand names and interview format to build credibility and increase the likelihood that targets will enter their login information on fraudulent sites.</description><pubDate>Mon, 06 Jul 2026 20:27:37 GMT</pubDate></item><item><title>Max severity Adobe ColdFusion flaw now exploited in attacks</title><link>https://bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks</link><guid isPermaLink="false">cst-2</guid><description>A critical Adobe ColdFusion vulnerability (CVE-2026-48282) is being actively exploited in the wild, according to KEVIntel. The flaw carries maximum severity rating and poses an immediate threat to organizations running affected ColdFusion instances.</description><pubDate>Mon, 06 Jul 2026 13:18:37 GMT</pubDate></item><item><title>It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)</title><link>https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza</link><guid isPermaLink="false">cst-554</guid><description>Adobe released a security advisory on June 30 addressing multiple critical vulnerabilities in ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below), including several arbitrary code execution flaws, privilege escalation issues, and file system access vulnerabilities. The analysis highlights that several vulnerabilities involve the Remote Development Services (RDS) feature, which requires being explicitly enabled and having authentication disabled to be exploited, and researchers note difficulty in mapping all disclosed CVEs to specific vulnerability details.</description><pubDate>Thu, 02 Jul 2026 16:38:28 GMT</pubDate></item><item><title>Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic</title><link>https://thehackernews.com/2026/07/adobe-patches-7-cvss-100-flaws-in.html</link><guid isPermaLink="false">cst-46</guid><description>Adobe released patches for multiple critical vulnerabilities in ColdFusion and Campaign Classic, including seven flaws with CVSS 10.0 scores that could enable arbitrary code execution, privilege escalation, file system read access, and security feature bypass. The patches address critical and important severity issues across both products.</description><pubDate>Wed, 01 Jul 2026 15:25:46 GMT</pubDate></item><item><title>Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls</title><link>https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html</link><guid isPermaLink="false">cst-53</guid><description>Anthropic restored access to Claude Fable 5 globally on July 1 after the U.S. Commerce Department lifted export controls that had been in place for approximately two and a half weeks. The model is now available across Claude.ai, the Claude Platform, Claude Code, and Claude Cowork.</description><pubDate>Wed, 01 Jul 2026 06:46:17 GMT</pubDate></item><item><title>‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm</title><link>https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm</link><guid isPermaLink="false">cst-131</guid><description>The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.</description><pubDate>Thu, 18 Jun 2026 17:37:58 GMT</pubDate></item><item><title>Srsly Risky Biz: Anthropic Lacks Emotional Intelligence</title><link>https://risky.biz/srsly-risky-biz-anthropic-lacks-emotional-intelligence</link><guid isPermaLink="false">cst-171</guid><description>Anthropic released two new AI models, Mythos 5 and Fable 5, but withdrew them within days after communications between Amazon CEO Andy Jassy and US officials raised concerns about potential jailbreaking vulnerabilities. The Commerce Department subsequently informed Anthropic that the models would be subject to export controls restricting their use by foreign nationals. The incident reflects ongoing friction between AI developers and the US government over model release practices and security standards.</description><pubDate>Thu, 18 Jun 2026 06:25:00 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>No Safe Distance: The Business Impact of Recent Global Developments</title><link>https://reliaquest.com/blog/threat-spotlight-no-safe-distance-the-business-impact-of-recent-global-developments</link><guid isPermaLink="false">cst-2205</guid><description>The US-Israel-Iran conflict is now affecting private companies and critical infrastructure beyond direct military involvement, with Iranian and pro-Iranian groups targeting cloud platforms, medical technology firms, point-of-sale systems, and launching DDoS attacks. Organizations are exposed through business relationships, supply chain roles, and geographic ties rather than direct participation in the conflict. The threat landscape is expanding from espionage toward disruption of critical infrastructure, suppliers, and connected devices.</description><pubDate>Thu, 12 Mar 2026 09:00:00 GMT</pubDate></item><item><title>The March 2026 Security Update Review</title><link>https://thezdi.com/blog/2026/3/10/the-march-2026-security-update-review</link><guid isPermaLink="false">cst-398</guid><description>Adobe released eight bulletins addressing 80 CVEs across multiple products including Acrobat Reader, Experience Manager, and Substance 3D tools in March 2026. Microsoft patched 84 CVEs in Windows, Office, Edge, Azure, and other components, with eight rated Critical severity and no active exploitation reported at release. Notable vulnerabilities include an Excel XSS bug exploitable by Copilot agents for data exfiltration and Office Preview Pane remote code execution issues.</description><pubDate>Tue, 10 Mar 2026 17:57:37 GMT</pubDate></item></channel></rss>