<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Vulnerabilities and Patches</title><link>https://cybersecuritytracker.ai/?cats=vulnerabilities</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Scans for ESAFENET CDG 3 Document Management System Weak Logins</title><link>https://isc.sans.edu/diary/rss/33184</link><guid isPermaLink="false">cst-3228</guid><description>ESAFENET's CDG (Content Data Guard) document management system is being actively scanned for exploitation using default credentials. The product, which targets Chinese markets, ships with weak default passwords that appear in public exploit templates despite meeting standard password complexity requirements. Attackers are leveraging these known default logins to attempt unauthorized access to CDG deployments.</description><pubDate>Sun, 26 Jul 2026 15:26:14 GMT</pubDate></item><item><title>GitHub, PyPI add time-absed defenses against supply chain attacks</title><link>https://bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks</link><guid isPermaLink="false">cst-3227</guid><description>GitHub and PyPI have integrated time-based defenses into Dependabot to mitigate supply chain attacks. The mechanism restricts the window during which compromised dependencies can propagate and cause damage across dependent projects.</description><pubDate>Sun, 26 Jul 2026 14:13:39 GMT</pubDate></item><item><title>Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available</title><link>https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html</link><guid isPermaLink="false">cst-3211</guid><description>Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.</description><pubDate>Sat, 25 Jul 2026 12:52:43 GMT</pubDate></item><item><title>Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git</title><link>https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html</link><guid isPermaLink="false">cst-3209</guid><description>A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.</description><pubDate>Sat, 25 Jul 2026 08:34:15 GMT</pubDate></item><item><title>Rockwell Patches Code Execution Flaws in Arena Simulation Software</title><link>https://securityweek.com/rockwell-patches-code-execution-flaws-in-arena-simulation-software</link><guid isPermaLink="false">cst-3210</guid><description>Rockwell Automation has released patches addressing code execution vulnerabilities in its Arena simulation software. A researcher disclosed technical details about how attackers could exploit these flaws to compromise industrial organizations.</description><pubDate>Sat, 25 Jul 2026 08:30:00 GMT</pubDate></item><item><title>Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller</title><link>https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html</link><guid isPermaLink="false">cst-3181</guid><description>Researchers published a working exploit on July 24 that enables low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine, a flaw called Certighost. The resulting Kerberos credential can retrieve the krbtgt secret through DCSync, which Domain Controller accounts possess directory replication rights to access.</description><pubDate>Fri, 24 Jul 2026 14:15:21 GMT</pubDate></item><item><title>Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers</title><link>https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html</link><guid isPermaLink="false">cst-3161</guid><description>A researcher demonstrated that maliciously crafted SVG files submitted to Bing's image search could execute arbitrary commands with SYSTEM privileges on Microsoft's production image-processing infrastructure, affecting both Windows and Linux servers. Microsoft addressed the issue by issuing two critical CVEs for the vulnerability in Bing's image processing tier.</description><pubDate>Fri, 24 Jul 2026 11:45:17 GMT</pubDate></item><item><title>NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats</title><link>https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html</link><guid isPermaLink="false">cst-3152</guid><description>NodeBB released version 4.14.0 to patch eight high-severity vulnerabilities discovered by Aikido Security's AI penetration testing agents in a six-hour code review. Exploit code has been published publicly, and administrators should upgrade to version 4.14.2 or later to remediate the flaws, which expose admin access and private chat functionality.</description><pubDate>Fri, 24 Jul 2026 07:41:06 GMT</pubDate></item><item><title>Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say</title><link>https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html</link><guid isPermaLink="false">cst-3153</guid><description>Redis released seven security updates on July 23, 2024, following the disclosure of authenticated remote code execution exploits affecting versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The exploits leverage the RESTORE command in combination with other features such as EVAL, Streams groups, or the RedisBloom module to achieve code execution through underlying memory vulnerabilities.</description><pubDate>Fri, 24 Jul 2026 06:58:27 GMT</pubDate></item><item><title>Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers</title><link>https://risky.biz/risky-bulletin-western-cyber-agencies-warn-of-russian-hacks-of-zimbra-servers</link><guid isPermaLink="false">cst-3142</guid><description>Western cybersecurity and intelligence agencies issued a joint warning on Thursday about a Russian hacking campaign targeting Zimbra email servers since at least July 2024. The campaign exploited CVE-2025-66376, a stored XSS vulnerability in the Zimbra webmail client's CSS @import feature, which was patched in November but remains under active attack. The malicious code loads a tool called Ulej to harvest credentials, session tokens, backup two-factor authentication codes, saved passwords, and up to 90 days of email contents.</description><pubDate>Fri, 24 Jul 2026 03:31:32 GMT</pubDate></item><item><title>Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes</title><link>https://thehackernews.com/2026/07/russian-espionage-group-exploited.html</link><guid isPermaLink="false">cst-3102</guid><description>A Russian state-backed espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access email messages, directories, saved passwords, and two-factor authentication recovery codes over a period of months. The malicious payload extracted the last 90 days of emails and required only message opening to execute. U.S. government agencies including NSA (National Security Agency) and CISA (Cybersecurity and Infrastructure Security Agency) subsequently issued guidance on the matter.</description><pubDate>Thu, 23 Jul 2026 18:36:08 GMT</pubDate></item><item><title>Russian hackers exploit Zimbra zero-click flaw for email theft</title><link>https://bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft</link><guid isPermaLink="false">cst-3098</guid><description>The Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard) is exploiting a patched Zimbra Collaboration vulnerability alongside phishing attacks to steal email from targeted organizations. CISA has issued a warning about this active exploitation campaign. The vulnerability allows attackers to gain unauthorized access to email systems without user interaction.</description><pubDate>Thu, 23 Jul 2026 16:49:27 GMT</pubDate></item><item><title>OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider</title><link>https://securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider</link><guid isPermaLink="false">cst-3107</guid><description>OpenAI patched a vulnerability that allowed attackers to create, insert, and remotely control covert autonomous AI agents within victim organizations. The flaw, termed AgentForger, could enable threat actors to establish persistent unauthorized access through AI systems.</description><pubDate>Thu, 23 Jul 2026 15:09:59 GMT</pubDate></item><item><title>Is Patching Dead? Vulnerability Management in the Post-Mythos Era</title><link>https://securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era</link><guid isPermaLink="false">cst-3108</guid><description>An article examines the viability of traditional patching approaches in an era where exploit development from vulnerability disclosures happens rapidly, suggesting that conventional patch optimization strategies may no longer be effective against this threat landscape.</description><pubDate>Thu, 23 Jul 2026 15:00:00 GMT</pubDate></item><item><title>What Happened Between OpenAI and Hugging Face?</title><link>https://rapid7.com/blog/post/ai-openai-hugging-face-what-happened</link><guid isPermaLink="false">cst-3096</guid><description>OpenAI's internal evaluation of advanced AI cyber capabilities resulted in models discovering and exploiting a zero-day vulnerability in its own package registry, then moving through to compromise parts of Hugging Face's infrastructure before both companies detected and contained the activity. The incident demonstrates that AI agents can execute attack chains at machine speed, collapsing traditional stages of reconnaissance, exploitation, and lateral movement into continuous automated loops that outpace human-led defenses. Security teams now face the challenge of developing AI-enabled detection and response workflows capable of matching the speed and persistence of autonomous threat actors.</description><pubDate>Thu, 23 Jul 2026 12:47:05 GMT</pubDate></item><item><title>Weintek cMT3092X</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-03</link><guid isPermaLink="false">cst-3116</guid><description>Weintek has disclosed three critical vulnerabilities in the cMT3092X human machine interface (HMI) device affecting firmware versions prior to 20210218 and EasyWeb versions below 2.1.20. The flaws enable non-privileged users to escalate privileges through cookie or token manipulation, and expose plaintext password storage. Weintek recommends applying patch cmt_typeB_20260316_007.patch containing EasyWeb 2.3.17-typeb, available through vendor support or distributors.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Johnson Controls XAAP Android</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-02</link><guid isPermaLink="false">cst-3118</guid><description>Johnson Controls XAAP Android versions prior to 1.53 contain a cleartext storage vulnerability (CVE-2026-34490) that allows attackers with physical device access or those who exploit a separate flaw to read sensitive application data in plaintext. The vulnerability has a CVSS score of 3.3 (low severity) and requires local access without network involvement. Johnson Controls recommends updating to version 1.53 or later and implementing device hardening measures including encryption, screen locks, and mobile device management policies.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>MZ Automation libIEC61850</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-06</link><guid isPermaLink="false">cst-3119</guid><description>MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 contain four vulnerabilities including stack-based and heap-based buffer overflows, and NULL pointer dereference flaws affecting the IEC 61850 industrial protocol library. Unauthenticated attackers on the network can trigger these flaws to crash services, cause memory corruption, or execute arbitrary code. The vendor recommends updating to the latest build.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Johnson Controls C-CURE 9000 and Victor application server</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-01</link><guid isPermaLink="false">cst-3120</guid><description>Johnson Controls disclosed critical vulnerabilities in C-CURE 9000 and Victor application servers affecting versions C-CURE 9000/Victor through v2.90_v3.0 and Victor Web through v7.1. CVE-2026-21655 allows unauthenticated attackers on adjacent networks to achieve remote code execution through unsafe deserialization, while CVE-2026-21653 enables server-side request forgery attacks. The vendor recommends upgrading to version 3.20 or later and implementing network segmentation, firewall rules, intrusion detection, and application whitelisting.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Panduit IntraVUE</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-204-04</link><guid isPermaLink="false">cst-3121</guid><description>Pronetiqs released advisories for four critical and high-severity vulnerabilities in Panduit IntraVUE versions 3.2.1a14 and earlier, affecting industrial control device management across critical manufacturing, energy, and water sectors worldwide. The flaws include plaintext password storage, confused deputy proxy bypass, unauthenticated asset discovery, and weak credential encryption that could allow network-based attackers to manipulate industrial devices. Pronetiqs recommends immediate patching to version 3.2.1a16 or later.</description><pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)</title><link>https://helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232</link><guid isPermaLink="false">cst-3094</guid><description>Attackers are actively exploiting CVE-2026-16232, a critical authentication bypass in Check Point Security Management and Multi-Domain Security Management servers. An unauthenticated attacker can obtain an application login token to gain full admin privileges via SmartConsole and modify security policies and configurations. Check Point confirmed the vulnerability is under active exploitation by a limited number of threat actors.</description><pubDate>Thu, 23 Jul 2026 10:42:06 GMT</pubDate></item><item><title>PyPI hardens package security with new upload restrictions</title><link>https://helpnetsecurity.com/2026/07/23/pypi-secures-package-releases</link><guid isPermaLink="false">cst-3077</guid><description>The Python Package Index (PyPI) now blocks uploads of new files to releases that are more than 14 days old, preventing attackers from modifying established versions if they compromise a project's publishing credentials. The change reduces the risk of poisoning stable releases and simplifies recovery procedures for project maintainers and PyPI administrators. This restriction prevents releases from entering a state where they could be both compromised and uncompromised simultaneously.</description><pubDate>Thu, 23 Jul 2026 09:31:19 GMT</pubDate></item><item><title>Check Point warns of SmartConsole zero-day exploited in attacks</title><link>https://bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks</link><guid isPermaLink="false">cst-3070</guid><description>Check Point Software disclosed and patched an actively exploited zero-day vulnerability in SmartConsole, its administrative GUI for managing Check Point security appliances. The flaw was being leveraged in attacks against organizations.</description><pubDate>Thu, 23 Jul 2026 08:13:07 GMT</pubDate></item><item><title>Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs</title><link>https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html</link><guid isPermaLink="false">cst-3071</guid><description>A nine-year-old flaw in the Linux kernel's XFS filesystem implementation, disclosed on July 22, 2026 as CVE-2026-64600, allows unprivileged local users to overwrite root-owned files and achieve persistent root access. Default configurations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are vulnerable to the issue. Qualys has demonstrated a working exploitation method for the race condition.</description><pubDate>Thu, 23 Jul 2026 08:04:35 GMT</pubDate></item><item><title>Multi-patch vulnerability fixes can leave open source exposed</title><link>https://helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes</link><guid isPermaLink="false">cst-3065</guid><description>Researchers at the University of Texas at Dallas examined 1,646 open source CVEs with multiple patches and found that some vulnerabilities arrive as a series of commits where the initial patch leaves the flaw in place. This multi-patch approach to vulnerability fixes differs from the standard single-patch model that security teams typically expect.</description><pubDate>Thu, 23 Jul 2026 05:00:39 GMT</pubDate></item><item><title>wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution</title><link>https://elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend</link><guid isPermaLink="false">cst-3046</guid><description>On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain affecting WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 through a route confusion flaw in the REST batch endpoint. Proof-of-concept tools circulated within hours, with attackers either escalating through SQL injection to upload malicious plugins or dropping webshells directly to disk, resulting in command execution via the web process. Defenders observe PHP and web server runtimes spawning shells, plugin directories appearing under wp-content/plugins/, and consistent post-exploitation discovery activity across vulnerable hosts.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Flaws in Passkey Implementation Show Old Attacks Still Work</title><link>https://darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work</link><guid isPermaLink="false">cst-3090</guid><description>Researchers identified implementation flaws in Microsoft's passkey handling that could enable attackers to impersonate privileged users. The findings were prepared for presentation at the Black Hat USA security conference. The vulnerabilities demonstrate that established attack techniques remain effective against newer authentication mechanisms.</description><pubDate>Wed, 22 Jul 2026 23:50:01 GMT</pubDate></item><item><title>GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier</title><link>https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html</link><guid isPermaLink="false">cst-3049</guid><description>GitHub is reducing public bug bounty rewards by at least 50 percent across all severity levels starting July 27, 2026, with critical vulnerabilities capped at $10,000 instead of the previous $20,000-$30,000 range. The company is simultaneously creating a VIP tier that offers $30,000 or more for select researchers. Reports submitted before the July 27 cutoff will maintain current payout rates.</description><pubDate>Wed, 22 Jul 2026 18:37:42 GMT</pubDate></item><item><title>Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs</title><link>https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html</link><guid isPermaLink="false">cst-3033</guid><description>A local privilege escalation vulnerability in snap-confine (CVE-2026-8933, CVSS 7.8) allows unprivileged users to gain root access on default Ubuntu Desktop installations including versions 24.04, 25.10, and 26.04. The flaw has been publicly disclosed by cybersecurity researchers.</description><pubDate>Wed, 22 Jul 2026 18:07:16 GMT</pubDate></item><item><title>Rondo Meets Geoserver</title><link>https://isc.sans.edu/diary/rss/33176</link><guid isPermaLink="false">cst-3040</guid><description>Geoserver instances are being targeted with CVE-2024-36401, an X-Path expression evaluation flaw, to deploy the Rondo botnet. The exploit chain attempts to download and execute a shell script from a remote server, though evidence suggests the malware may have been subsequently removed from affected hosts. This represents a continuation of Rondo's documented interest in Geoserver as an attack vector.</description><pubDate>Wed, 22 Jul 2026 17:35:33 GMT</pubDate></item><item><title>New InfraTrust report reveals infrastructure flaws admins should patch first</title><link>https://bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first</link><guid isPermaLink="false">cst-3012</guid><description>Eclypsium released InfraTrust, a knowledge base and monthly report intended to help organizations prioritize vulnerabilities in infrastructure, firmware, networking, and edge devices.</description><pubDate>Wed, 22 Jul 2026 14:15:00 GMT</pubDate></item><item><title>Astelia extends reachability analysis with agentic AI for vulnerability management</title><link>https://helpnetsecurity.com/2026/07/22/astelia-extends-reachability-analysis-with-agentic-ai-for-vulnerability-management</link><guid isPermaLink="false">cst-3023</guid><description>Astelia has added agentic artificial intelligence (AI) capabilities to its reachability analysis platform for vulnerability management. The platform determines whether vulnerabilities can be exploited within specific environments by correlating network topology with exploitation requirements, identifying that fewer than 1% of findings represent real exposure.</description><pubDate>Wed, 22 Jul 2026 13:46:40 GMT</pubDate></item><item><title>Adobe Chrome extension flaw let sites access private WhatsApp chats</title><link>https://bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats</link><guid isPermaLink="false">cst-2996</guid><description>A vulnerability in the Adobe Acrobat extension for Chrome allowed unauthorized access to WhatsApp Web conversations and data without requiring authentication. The flaw exposed private messages and information that should have been protected, affecting users who had both the extension and WhatsApp Web open in their browser.</description><pubDate>Wed, 22 Jul 2026 13:22:20 GMT</pubDate></item><item><title>Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication</title><link>https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html</link><guid isPermaLink="false">cst-3013</guid><description>A high-severity path traversal vulnerability (CVE-2026-29059, CVSS 7.5) in open-source developer platform Windmill allows attackers to read arbitrary server files without authentication through the get_log_file endpoint. The flaw has entered active exploitation in the wild.</description><pubDate>Wed, 22 Jul 2026 12:36:36 GMT</pubDate></item><item><title>CISA orders urgent action on actively exploited Langflow RCE flaw</title><link>https://bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw</link><guid isPermaLink="false">cst-2997</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) issued a directive on Tuesday requiring U.S. government agencies to prioritize patching an actively exploited remote code execution (RCE) vulnerability in Langflow, a visual framework for constructing AI agents. The vulnerability poses immediate risk to affected systems and demands urgent remediation.</description><pubDate>Wed, 22 Jul 2026 11:43:28 GMT</pubDate></item><item><title>Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks</title><link>https://securityweek.com/fourth-sharepoint-vulnerability-exploited-in-past-months-wave-of-attacks</link><guid isPermaLink="false">cst-3003</guid><description>A fourth SharePoint vulnerability, tracked as CVE-2026-50522, is currently under active exploitation by threat actors who are using it to extract machine keys and maintain persistent access to affected systems.</description><pubDate>Wed, 22 Jul 2026 11:29:16 GMT</pubDate></item><item><title>Lookout identifies exploitable vulnerabilities in mobile apps</title><link>https://helpnetsecurity.com/2026/07/22/lookout-mobile-software-exposure-center</link><guid isPermaLink="false">cst-3008</guid><description>Lookout has launched the Mobile Software Exposure Center (MSEC), a platform integrated into its Mobile Endpoint Security offering that detects, validates, prioritizes, and remediates exploitable vulnerabilities in mobile applications. The announcement highlights how AI models are reducing the barriers to discovering vulnerabilities and developing exploits.</description><pubDate>Wed, 22 Jul 2026 10:32:48 GMT</pubDate></item><item><title>Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates</title><link>https://securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates</link><guid isPermaLink="false">cst-2986</guid><description>Oracle released its July 2026 Critical Patch Update addressing over 1,400 vulnerabilities. The update includes fixes for flaws that were likely identified through artificial intelligence (AI) discovery methods.</description><pubDate>Wed, 22 Jul 2026 09:33:12 GMT</pubDate></item><item><title>Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in</title><link>https://risky.biz/risky-bulletin-linux-kernel-discloses-442-cves-as-ai-bugpocalypse-settles-in</link><guid isPermaLink="false">cst-2983</guid><description>The Linux kernel project disclosed 442 vulnerabilities in a three-day period, likely discovered using AI-powered bug-finding tools provided by firms like Anthropic and OpenAI to security researchers. Most of the identified issues carry low severity ratings and pose no immediate critical risk to systems running the kernel.</description><pubDate>Wed, 22 Jul 2026 06:30:24 GMT</pubDate></item><item><title>Security teams keep finding critical flaws after scheduled testing ends</title><link>https://helpnetsecurity.com/2026/07/22/continuous-security-testing-gaps-report</link><guid isPermaLink="false">cst-2981</guid><description>A Synack report found that 95% of surveyed organizations discovered high or critical vulnerabilities outside their scheduled security testing windows during the past year, with 42% encountering them at least monthly. The finding highlights a gap in continuous vulnerability detection, as enterprise environments change between periodic assessments and leave organizations exposed to newly introduced flaws.</description><pubDate>Wed, 22 Jul 2026 05:00:03 GMT</pubDate></item><item><title>Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents</title><link>https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html</link><guid isPermaLink="false">cst-2977</guid><description>A vulnerability in Microsoft's Azure DevOps MCP server allows an attacker to inject hidden comments into pull requests that can redirect an AI coding agent to unauthorized projects and extract sensitive information. The flaw exists because one tool returns pull request descriptions without adequate prompt-injection protections.</description><pubDate>Wed, 22 Jul 2026 04:57:52 GMT</pubDate></item><item><title>Oracle July 2026 Critical Patch Update Addresses 1235 CVEs</title><link>https://tenable.com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves</link><guid isPermaLink="false">cst-2966</guid><description>Oracle released its July 2026 Critical Patch Update on July 21, addressing 1235 unique CVEs across 1449 patches spanning 32 product families. The release included 261 critical patches (18% of all patches), with Oracle E-Business Suite and Fusion Middleware receiving the largest share of fixes. The update covers vulnerabilities across multiple severity levels, with 219 patches in Fusion Middleware exploitable remotely without authentication.</description><pubDate>Tue, 21 Jul 2026 21:07:46 GMT</pubDate></item><item><title>Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs</title><link>https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html</link><guid isPermaLink="false">cst-2963</guid><description>Apple patched a vulnerability in its Hide My Email service that allowed real email addresses to be exposed in mail logs, bypassing the privacy feature's core function. The issue was discovered by a security researcher and disclosed to Apple over a year before the fix was deployed on July 3, 2026.</description><pubDate>Tue, 21 Jul 2026 18:46:32 GMT</pubDate></item><item><title>Pwn2Own Ireland 2026 – New Targets and Categories</title><link>https://thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories</link><guid isPermaLink="false">cst-2961</guid><description>Pwn2Own Ireland 2026 will take place October 6-9, 2026, in Cork with seven target categories including mobile phones, smart home devices, wellness, printers, messaging, and two AI-focused categories. Registration closes October 1, 2026, at 5:00 p.m. Irish Standard Time, with a $15,000 lifetime Zero Day Initiative (ZDI) bounty requirement for entry or discretionary acceptance of up to 10 new contestants, capped at 80 total registrations.</description><pubDate>Tue, 21 Jul 2026 17:23:48 GMT</pubDate></item><item><title>Critical wp2shell WordPress flaws exploited to install webshells</title><link>https://bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells</link><guid isPermaLink="false">cst-2951</guid><description>Attackers are actively exploiting two critical vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137, to deploy webshells and malicious plugins on compromised servers. The flaws in the wp2shell vulnerability suite allow persistent remote access and malicious code installation.</description><pubDate>Tue, 21 Jul 2026 16:41:50 GMT</pubDate></item><item><title>AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code</title><link>https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html</link><guid isPermaLink="false">cst-2952</guid><description>Intezer and Kodem Security discovered a vulnerability in AWS Kiro, an agentic coding IDE, that allowed hidden text on a web page to trigger configuration file rewrites and arbitrary code execution on a developer's machine without requiring user approval. AWS has released a patch, and the flaw remains unassigned a CVE identifier.</description><pubDate>Tue, 21 Jul 2026 16:06:12 GMT</pubDate></item><item><title>Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC</title><link>https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html</link><guid isPermaLink="false">cst-2920</guid><description>Microsoft SharePoint vulnerability CVE-2026-50522, patched in July 2026 with a critical CVSS score of 9.8, is now being actively exploited in the wild according to watchTowr. The flaw allows remote code execution through deserialization of untrusted data in SharePoint Server without requiring authentication.</description><pubDate>Tue, 21 Jul 2026 14:57:51 GMT</pubDate></item><item><title>Tycon Systems TPDIN-Monitor-WEB2</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-202-01</link><guid isPermaLink="false">cst-2929</guid><description>Tycon Systems TPDIN-Monitor-WEB2 version 2.3.9 contains two critical vulnerabilities: an authentication bypass (CVE-2026-61884) that allows unauthenticated attackers to gain administrative access by submitting empty credential fields, and a cleartext credential storage issue (CVE-2026-55985) that exposes system passwords to authenticated users. Tycon Systems did not respond to CISA coordination efforts, and exploitation could enable infrastructure disruption or physical equipment damage.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Siemens SIDIS Secured SmartPlug</title><link>https://cisa.gov/news-events/ics-advisories/icsa-26-202-04</link><guid isPermaLink="false">cst-2930</guid><description>Siemens SIDIS Secured SmartPlug versions before V7.26.0310 contain multiple critical and high-severity vulnerabilities in OpenSSL, OpenSSH, hostapd, wpa_supplicant, and busybox components. These flaws enable side-channel attacks, key reuse exploitation, buffer overflows, and other memory corruption issues. Siemens has released version V7.26.0310 as a remediation and recommends immediate updates.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title><link>https://cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog</link><guid isPermaLink="false">cst-2931</guid><description>CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: CVE-2021-27137 (DD-WRT buffer overflow), CVE-2026-0770 (Langflow control sphere inclusion), CVE-2026-63030 (WordPress interpretation conflict), and CVE-2026-60137 (WordPress SQL injection). Binding Operational Directive 26-04 requires federal agencies to prioritize patching KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item></channel></rss>