Tech & Science

56

F5 and NGINX Patch Critical Vulnerability Allowing Remote Code Execution

Tech & ScienceAI·1 source·

SAN FRANCISCO — F5 Inc. and the open-source NGINX project released emergency patches on Sunday, July 19, to address a critical vulnerability in the widely used web server software that could allow att...

56

New Threat Actor Exploits Zero-Day Flaws in SonicWall VPN Appliances to Steal Credentials

Tech & ScienceAI·1 source·

A previously unidentified cyber threat actor designated UTA0533 has successfully exploited two zero-day vulnerabilities in SonicWall SMA 1000 series Virtual Private Network (VPN) appliances, gaining r...

56

Incode Technologies Launches On-Device Age Estimation Tool to Address Global Privacy Concerns

Tech & ScienceAI·1 source·

SINGAPORE (July 18, 2026) — Incode Technologies launched a new on-device age estimation product Thursday, introducing a system designed to process facial data locally without transmitting or storing i...

56

7-Zip Releases Emergency Patch for Critical Remote Code Execution Flaw

Tech & ScienceAI·1 source·

Developers of the popular open-source file archiver 7-Zip released version 26.02 on Friday to address a critical security vulnerability allowing remote code execution through malicious archives. The u...

56

WordPress Issues Urgent Patches for Critical Remote Code Execution Flaw

Tech & ScienceAI·1 source·

SAN FRANCISCO — WordPress released emergency security updates on Thursday to address a critical vulnerability in its core software that allows unauthenticated attackers to execute arbitrary code remot...

56

Abbott Laboratories Investigates Two Cybersecurity Incidents Involving Extortion Claims

Tech & ScienceAI·1 source·

CHICAGO — Abbott Laboratories announced on July 17, 2026, that it is investigating two separate cybersecurity incidents involving unauthorized access to internal systems and potential data breaches. T...

56

SuccessKey Discovers Malicious NPM Packages Exploiting Blockchain for Vite Attacks

Tech & ScienceAI·1 source·

SAN FRANCISCO (AP) — Security firm SuccessKey identified seven malicious software packages on the npm registry that target developers using the Vite frontend tooling ecosystem, utilizing a blockchain-...

56

Cyberattack Halts Operations at Japanese Frozen Food Giant Nichirei

Tech & ScienceAI·1 source·

TOKYO — A cyberattack by unidentified hackers has severely disrupted operations at Nichirei Corp., one of Japan's largest frozen food producers, forcing the company to halt activities across its refri...

56

Chinese Cyber Group CylindricalCanine Breaches DigiCert to Steal Code-Signing Certificates

Tech & ScienceAI·1 source·

SAN FRANCISCO — A subgroup of the Chinese cybercrime organization GoldenEyeDog, identified as CylindricalCanine, successfully breached certificate authority DigiCert in early April 2026, stealing code...

56

EY Discloses Data Breach of Third-Party Support System Affecting IT Personnel

Tech & ScienceAI·1 source·

LONDON — Ernst & Young disclosed on Wednesday that unauthorized actors gained access to a third-party support ticket system used by its information technology personnel, marking the latest security in...

56

EU Orders Google to Open Android Features to Rival AI Assistants by 2027

Tech & ScienceAI·1 source·

BRUSSELS — The European Commission has ordered Alphabet Inc.'s Google to grant rival artificial intelligence assistants access to critical Android operating system features, including the microphone, ...

56

Kaspersky Researchers Identify New GoSerpent Malware Campaign Targeting Southeast Asian Diplomats

Tech & ScienceAI·1 source·

MOSCOW — Russian cybersecurity firm Kaspersky announced on Wednesday the discovery of a sophisticated espionage campaign utilizing new malware variants to target government officials and diplomatic en...

56

Microsoft Defender Experts Detect Surge in ACR Stealer Activity Using ClickFix Lures

Tech & ScienceAI·1 source·

REDMOND, Wash. — Microsoft Defender Experts observed a significant increase in activity involving the ACR Stealer malware across customer environments on Wednesday, July 16, 2026. The malicious campai...

56

Microsoft Windows Server 2022 Enters Final Mainstream Support Phase Ahead of 2026 Transition

Tech & ScienceAI·1 source·

REDMOND, Wash. — Microsoft announced that its Windows Server 2022 operating system will reach the end of mainstream support in October 2026, marking a significant milestone in the software's lifecycle...

56

CISA Orders Urgent Patching of Fortinet Vulnerabilities Amid Active Exploitation

Tech & ScienceAI·1 source·

WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive to federal agencies, mandating the immediate patching of two critical vulnerabilities in...

56

Ransomware Attack Halts Production at Coca-Cola's Fairlife Dairy Facilities Across U.S.

Tech & ScienceAI·1 source·

ATLANTA — A sophisticated ransomware attack has forced the temporary suspension of production operations at multiple United States facilities owned by Fairlife, a premium dairy brand under The Coca-Co...

56

n8n Addresses Critical JWT Flaw Allowing Cross-Issuer Account Takeovers in Enterprise Feature

Tech & ScienceAI·1 source·

BERLIN — Workflow automation platform n8n disclosed a critical security vulnerability on July 16, 2026, that allowed attackers to bypass identity verification and gain unauthorized access to enterpris...

69

New macOS Stealer ClickLock Disables Applications to Force Credential Theft

Tech & ScienceAI·1 source··UPDATED

A sophisticated new infostealing malware targeting Apple computers has emerged, employing an aggressive tactic of forcibly terminating user applications every 210 milliseconds until victims surrender ...

56

New AI Vulnerability Allows Attackers to Hijack Trusted Agent Commands

Tech & ScienceAI·1 source·

SEOUL — A coalition of researchers from Seoul National University, the University of Illinois Urbana-Champaign, and technology firm Largosoft has demonstrated a new class of artificial intelligence at...

56

Microsoft Sets July Deadline for End of Support on Key Windows Editions

Tech & ScienceAI·1 source·

REDMOND, Wash. — Microsoft announced that support for several key versions of its operating system will conclude in three months, marking the end of mainstream lifecycle coverage for specific editions...

56

SharkNinja Vacuums Left Vulnerable to Remote Hacking After Delayed Patch

Tech & ScienceAI·1 source·

LONDON (July 13, 2026) — A critical security flaw in SharkNinja robotic vacuums allows attackers to seize control of devices across global regions by exploiting an unpatched error in Amazon Web Servic...

56

Russian Cyber Group Targets Global Users with Trojanized Software Installers

Tech & ScienceAI·1 source·

A financially motivated Russian cyber threat actor, tracked under the designation UAT-11795, has launched a widespread campaign deploying Starland Remote Access Trojans (RAT) by compromising legitimat...

56

Security Researcher Discloses Windows Zero-Day Over Dispute With Microsoft

Tech & ScienceAI·1 source·

A security researcher known by the pseudonym Chaotic Eclipse has publicly disclosed a new zero-day exploit targeting fully patched versions of the Windows operating system, escalating a long-standing ...

73

Zoom Issues Urgent Alert Over Critical Account Takeover Flaw in Windows Clients

Tech & ScienceAI·1 source··UPDATED

SAN FRANCISCO (July 15, 2026) — Video conferencing giant Zoom issued an urgent security advisory on Tuesday warning of a critical vulnerability that could allow attackers to hijack user accounts acros...

56

Malicious AsyncAPI Packages Target Developer Credentials in Supply Chain Attack

Tech & ScienceAI·1 source·

LONDON (July 15, 2026) — A threat actor exploited a misconfigured GitHub Actions workflow to publish five malicious versions of popular AsyncAPI packages on the npm registry, launching a supply-chain ...

56

CISA Urges Immediate Action as Hackers Exploit Critical SharePoint Flaws

Tech & ScienceAI·1 source·

WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on Monday, July 14, directing organizations to immediately harden their Microsoft SharePoint Ser...

69

SonicWall Urges Immediate Patching as Critical Zero-Day Attacks Target SMA1000 Appliances

Tech & ScienceAI·1 source··UPDATED

SAN JOSE, Calif. (July 14, 2026) — Network security firm SonicWall issued an urgent advisory on Monday warning that two critical vulnerabilities in its SMA1000 application delivery controllers are bei...

56

Threat Actor Deploys Nearly 300 Fake GitHub Repositories to Distribute Infostealer Malware

Tech & ScienceAI·1 source·

A financially motivated threat actor, likely Russian-speaking, has published nearly 300 fake repositories on the code-sharing platform GitHub designed to impersonate legitimate software and distribute...

77

Microsoft Issues Record-Breaking Patches for 622 Vulnerabilities Amid Active Directory Exploits

Tech & ScienceAI·1 source··UPDATED

REDMOND, Wash. — Microsoft released a record-breaking batch of security updates on Wednesday to address 622 vulnerabilities across its software portfolio, including two actively exploited zero-day fla...

63

Microsoft Deploys July 2026 Security Patches for Windows 11 Amid Feature Updates

Tech & ScienceAI·1 source·

REDMOND, Wash. (AP) — Microsoft released critical security updates and feature enhancements for its Windows 11 operating system on Thursday morning, addressing vulnerabilities identified in the compan...