# Archive

Browse past daily curated stories

Jul 21 Jul 19 Jul 18 Jul 17 Jul 16 Jul 15 Jul 14 Jul 12 Jul 11 Jul 10 Jul 09 Jul 08 Jul 07 Jul 05 Jul 04 Jul 03 Jul 02 Jul 01 Jun 30 Jun 27 Jun 26 Jun 25 Jun 24 Jun 23 Jun 21 Jun 20 Jun 19 Jun 18 Jun 17 Jun 16

Tuesday, July 21, 2026

  1. 1
    0
    The Hacker News general
    SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

    Threat actor UTA0533 (tracked by Volexity) exploited two SonicWall SMA 1000 series VPN appliance zero-days — CVE-2026-15409 and CVE-2026-15410 — beginning as early as June 22, 2026, weeks before public disclosure, achieving root access and deploying custom malware. The pre-patch exploitation window and targeting of widely-deployed VPN infrastructure makes this critical for organizations running SMA1000 appliances to investigate for compromise indicators immediately.

  2. 2
    0
    BleepingComputer general
    Critical ServiceNow code execution flaw now exploited in attacks

    Active exploitation has begun against CVE-2026-6875, a critical remote code execution vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. ServiceNow is widely deployed across enterprise IT and ITSM environments, making active exploitation of a code execution flaw a high-priority patching event for security teams.

  3. 3
    0
    Dark Reading general
    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Attackers began chaining CVE-2026-60137 and CVE-2026-63030 (dubbed 'WP2Shell') within three days of disclosure to target millions of WordPress sites with remote takeover attempts. The rapid weaponization against one of the internet's largest attack surfaces demands immediate patching for any WordPress installation running the affected components.

  4. 4
    0
    BleepingComputer general
    Hugging Face discloses breach linked to autonomous AI agent

    Hugging Face, the world's largest AI model repository, disclosed a breach of its production infrastructure via an autonomous AI agent system, with attackers accessing internal datasets and service credentials. The incident is notable as a documented case of an agentic AI being used offensively against a major ML platform, raising supply chain concerns for the AI/ML community.

  5. 5
    0
    The Hacker News general
    Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

    A Dutch intelligence advisory (AIVD/MIVD, published July 10) confirmed that at least one Russian intelligence service is systematically hijacking internet-connected IP cameras across NATO states and Ukraine to surveil military logistics, weapons shipments to Kyiv, and troop positions. The campaign demonstrates ongoing Russian signals intelligence collection against Western military supply chains using commodity IoT devices.

  6. 6
    0
    The Hacker News general
    UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

    UAC-0145, a sub-cluster of Russia's GRU-affiliated Sandworm group, is using ClickFix fake CAPTCHA lures to trick Ukrainian targets into self-installing data-stealing malware, per CERT-UA attribution. The technique bypasses traditional delivery mechanisms by socially engineering victims into executing the malware themselves, a tactic increasingly adopted by state-sponsored actors.

  7. 7
    0
    The Hacker News general
    FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

    Researchers identified the FakeGit campaign operating nearly 7,600 malicious GitHub repositories — over 800 posing as AI tools or MCP servers — distributing a malware family called SmartLoader. The campaign exploits developer trust in GitHub and the current AI tooling ecosystem, representing a significant software supply chain threat targeting the security and developer communities.

  8. 8
    0
    The Hacker News general
    SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

    The SleeperGem supply chain attack published three malicious RubyGems packages to RubyGems.org starting July 18, 2026, including git_credential_manager (versions 2.8.0–2.8.3) and Dendreo (versions 1.1.3–1.1.4), designed to serve additional payloads on developer machines. Targeting a package impersonating git credential management is particularly dangerous given its access to developer authentication tokens.

  9. 9
    0
    The Hacker News general
    Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    F5 patched CVE-2026-42533 on July 15, 2026 — a critical heap buffer overflow in NGINX worker processes triggerable by unauthenticated remote attackers via crafted HTTP requests — in nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1. Given NGINX's ubiquity as a web server and reverse proxy, unpatched instances face potential crash or RCE risk from any external attacker.

  10. 10
    0
    BleepingComputer general
    New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

    Group-IB researchers identified HollowGraph, an espionage implant that abuses the Microsoft Graph API to use compromised Microsoft 365 calendar events — dated to year 2050 — as a covert C2 channel, smuggling commands and exfiltrated files as calendar attachments to blend into legitimate M365 traffic. The technique evades network detection tools that whitelist Microsoft Graph API communications, posing a detection challenge for enterprise defenders.