<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Trend Micro Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Trend Micro.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction</title><link>https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html</link><guid isPermaLink="false">cst-2816</guid><description>A heap-based buffer overflow in 7-Zip's XZ archive processing (CVE-2026-14266) allows remote code execution when opening malicious files. The vulnerability was disclosed by Trend Micro's Zero Day Initiative on July 15, with a patch available since June 25 in version 26.02.</description><pubDate>Mon, 20 Jul 2026 09:10:56 GMT</pubDate></item><item><title>Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities</title><link>https://securityweek.com/trend-micro-tanium-eset-and-tenable-patch-severe-product-vulnerabilities</link><guid isPermaLink="false">cst-2644</guid><description>Cybersecurity vendors Trend Micro, Tanium, ESET, and Tenable released patches for critical and high-severity vulnerabilities in their products. The article provides no details on affected products, vulnerability types, or patch availability.</description><pubDate>Thu, 16 Jul 2026 06:08:08 GMT</pubDate></item><item><title>Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record</title><link>https://cyberscoop.com/microsoft-patch-tuesday-july-2026</link><guid isPermaLink="false">cst-2535</guid><description>Microsoft disclosed 622 vulnerabilities during July 2026 Patch Tuesday, more than triple the previous month's record of 206 and reflecting an exponential surge driven by artificial intelligence tools discovering defects at scale. Two actively exploited zero-day vulnerabilities in Active Directory Federation Services and SharePoint Server were included among the batch, with 63 rated as critical. The pace suggests Microsoft will exceed 2,000 or more Common Vulnerabilities and Exposures (CVEs) for the calendar year, far surpassing historical annual records.</description><pubDate>Tue, 14 Jul 2026 20:05:46 GMT</pubDate></item><item><title>Phishers Gain Persistence at EU, Asia Hospitality Orgs</title><link>https://darkreading.com/cyberattacks-data-breaches/phishers-persistence-eu-asia-hospitality-orgs</link><guid isPermaLink="false">cst-90</guid><description>Microsoft and Trend Micro have identified separate but coordinated phishing campaigns targeting hospitality organizations in the EU and Asia. The attacks use malicious zip files with social engineering and obfuscation techniques, including abuse of blockchain services, to establish persistent malware infections.</description><pubDate>Tue, 30 Jun 2026 18:59:46 GMT</pubDate></item><item><title>‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm</title><link>https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm</link><guid isPermaLink="false">cst-131</guid><description>The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.</description><pubDate>Thu, 18 Jun 2026 17:37:58 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>