# Archive

Browse past daily curated stories

Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22

Tuesday, July 21, 2026

  1. 1
    1
    The Hacker News general
    SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

    Threat actor UTA0533 (tracked by Volexity) exploited two SonicWall SMA 1000 series VPN appliance zero-days — CVE-2026-15409 and CVE-2026-15410 — beginning as early as June 22, 2026, weeks before public disclosure, achieving root access and deploying custom malware. The pre-patch exploitation window and targeting of widely-deployed VPN infrastructure makes this critical for organizations running SMA1000 appliances to investigate for compromise indicators immediately.

  2. 2
    0
    BleepingComputer general
    Critical ServiceNow code execution flaw now exploited in attacks

    Active exploitation has begun against CVE-2026-6875, a critical remote code execution vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. ServiceNow is widely deployed across enterprise IT and ITSM environments, making active exploitation of a code execution flaw a high-priority patching event for security teams.

  3. 3
    0
    Dark Reading general
    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Attackers began chaining CVE-2026-60137 and CVE-2026-63030 (dubbed 'WP2Shell') within three days of disclosure to target millions of WordPress sites with remote takeover attempts. The rapid weaponization against one of the internet's largest attack surfaces demands immediate patching for any WordPress installation running the affected components.

  4. 4
    0
    BleepingComputer general
    Hugging Face discloses breach linked to autonomous AI agent

    Hugging Face, the world's largest AI model repository, disclosed a breach of its production infrastructure via an autonomous AI agent system, with attackers accessing internal datasets and service credentials. The incident is notable as a documented case of an agentic AI being used offensively against a major ML platform, raising supply chain concerns for the AI/ML community.

  5. 5
    0
    The Hacker News general
    Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

    A Dutch intelligence advisory (AIVD/MIVD, published July 10) confirmed that at least one Russian intelligence service is systematically hijacking internet-connected IP cameras across NATO states and Ukraine to surveil military logistics, weapons shipments to Kyiv, and troop positions. The campaign demonstrates ongoing Russian signals intelligence collection against Western military supply chains using commodity IoT devices.

  6. 6
    0
    The Hacker News general
    UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

    UAC-0145, a sub-cluster of Russia's GRU-affiliated Sandworm group, is using ClickFix fake CAPTCHA lures to trick Ukrainian targets into self-installing data-stealing malware, per CERT-UA attribution. The technique bypasses traditional delivery mechanisms by socially engineering victims into executing the malware themselves, a tactic increasingly adopted by state-sponsored actors.

  7. 7
    0
    The Hacker News general
    FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

    Researchers identified the FakeGit campaign operating nearly 7,600 malicious GitHub repositories — over 800 posing as AI tools or MCP servers — distributing a malware family called SmartLoader. The campaign exploits developer trust in GitHub and the current AI tooling ecosystem, representing a significant software supply chain threat targeting the security and developer communities.

  8. 8
    0
    The Hacker News general
    SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

    The SleeperGem supply chain attack published three malicious RubyGems packages to RubyGems.org starting July 18, 2026, including git_credential_manager (versions 2.8.0–2.8.3) and Dendreo (versions 1.1.3–1.1.4), designed to serve additional payloads on developer machines. Targeting a package impersonating git credential management is particularly dangerous given its access to developer authentication tokens.

  9. 9
    0
    The Hacker News general
    Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    F5 patched CVE-2026-42533 on July 15, 2026 — a critical heap buffer overflow in NGINX worker processes triggerable by unauthenticated remote attackers via crafted HTTP requests — in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Given NGINX's ubiquity as a web server and reverse proxy, unpatched instances face potential crash or RCE risk from any external attacker.

  10. 10
    0
    BleepingComputer general
    New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

    Group-IB researchers identified HollowGraph, an espionage implant that abuses the Microsoft Graph API to use compromised Microsoft 365 calendar events — dated to year 2050 — as a covert C2 channel, smuggling commands and exfiltrated files as calendar attachments to blend into legitimate M365 traffic. The technique evades network detection tools that whitelist Microsoft Graph API communications, posing a detection challenge for enterprise defenders.