Tech & Science
F5 and NGINX Patch Critical Vulnerability Allowing Remote Code Execution
SAN FRANCISCO — F5 Inc. and the open-source NGINX project released emergency patches on Sunday, July 19, to address a critical vulnerability in the widely used web server software that could allow att...
New Threat Actor Exploits Zero-Day Flaws in SonicWall VPN Appliances to Steal Credentials
A previously unidentified cyber threat actor designated UTA0533 has successfully exploited two zero-day vulnerabilities in SonicWall SMA 1000 series Virtual Private Network (VPN) appliances, gaining r...
Incode Technologies Launches On-Device Age Estimation Tool to Address Global Privacy Concerns
SINGAPORE (July 18, 2026) — Incode Technologies launched a new on-device age estimation product Thursday, introducing a system designed to process facial data locally without transmitting or storing i...
7-Zip Releases Emergency Patch for Critical Remote Code Execution Flaw
Developers of the popular open-source file archiver 7-Zip released version 26.02 on Friday to address a critical security vulnerability allowing remote code execution through malicious archives. The u...
WordPress Issues Urgent Patches for Critical Remote Code Execution Flaw
SAN FRANCISCO — WordPress released emergency security updates on Thursday to address a critical vulnerability in its core software that allows unauthenticated attackers to execute arbitrary code remot...
Abbott Laboratories Investigates Two Cybersecurity Incidents Involving Extortion Claims
CHICAGO — Abbott Laboratories announced on July 17, 2026, that it is investigating two separate cybersecurity incidents involving unauthorized access to internal systems and potential data breaches. T...
SuccessKey Discovers Malicious NPM Packages Exploiting Blockchain for Vite Attacks
SAN FRANCISCO (AP) — Security firm SuccessKey identified seven malicious software packages on the npm registry that target developers using the Vite frontend tooling ecosystem, utilizing a blockchain-...
Cyberattack Halts Operations at Japanese Frozen Food Giant Nichirei
TOKYO — A cyberattack by unidentified hackers has severely disrupted operations at Nichirei Corp., one of Japan's largest frozen food producers, forcing the company to halt activities across its refri...
Chinese Cyber Group CylindricalCanine Breaches DigiCert to Steal Code-Signing Certificates
SAN FRANCISCO — A subgroup of the Chinese cybercrime organization GoldenEyeDog, identified as CylindricalCanine, successfully breached certificate authority DigiCert in early April 2026, stealing code...
EY Discloses Data Breach of Third-Party Support System Affecting IT Personnel
LONDON — Ernst & Young disclosed on Wednesday that unauthorized actors gained access to a third-party support ticket system used by its information technology personnel, marking the latest security in...
EU Orders Google to Open Android Features to Rival AI Assistants by 2027
BRUSSELS — The European Commission has ordered Alphabet Inc.'s Google to grant rival artificial intelligence assistants access to critical Android operating system features, including the microphone, ...
Kaspersky Researchers Identify New GoSerpent Malware Campaign Targeting Southeast Asian Diplomats
MOSCOW — Russian cybersecurity firm Kaspersky announced on Wednesday the discovery of a sophisticated espionage campaign utilizing new malware variants to target government officials and diplomatic en...
Microsoft Defender Experts Detect Surge in ACR Stealer Activity Using ClickFix Lures
REDMOND, Wash. — Microsoft Defender Experts observed a significant increase in activity involving the ACR Stealer malware across customer environments on Wednesday, July 16, 2026. The malicious campai...
Microsoft Windows Server 2022 Enters Final Mainstream Support Phase Ahead of 2026 Transition
REDMOND, Wash. — Microsoft announced that its Windows Server 2022 operating system will reach the end of mainstream support in October 2026, marking a significant milestone in the software's lifecycle...
CISA Orders Urgent Patching of Fortinet Vulnerabilities Amid Active Exploitation
WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive to federal agencies, mandating the immediate patching of two critical vulnerabilities in...
Ransomware Attack Halts Production at Coca-Cola's Fairlife Dairy Facilities Across U.S.
ATLANTA — A sophisticated ransomware attack has forced the temporary suspension of production operations at multiple United States facilities owned by Fairlife, a premium dairy brand under The Coca-Co...
n8n Addresses Critical JWT Flaw Allowing Cross-Issuer Account Takeovers in Enterprise Feature
BERLIN — Workflow automation platform n8n disclosed a critical security vulnerability on July 16, 2026, that allowed attackers to bypass identity verification and gain unauthorized access to enterpris...
New macOS Stealer ClickLock Disables Applications to Force Credential Theft
A sophisticated new infostealing malware targeting Apple computers has emerged, employing an aggressive tactic of forcibly terminating user applications every 210 milliseconds until victims surrender ...
New AI Vulnerability Allows Attackers to Hijack Trusted Agent Commands
SEOUL — A coalition of researchers from Seoul National University, the University of Illinois Urbana-Champaign, and technology firm Largosoft has demonstrated a new class of artificial intelligence at...
Microsoft Sets July Deadline for End of Support on Key Windows Editions
REDMOND, Wash. — Microsoft announced that support for several key versions of its operating system will conclude in three months, marking the end of mainstream lifecycle coverage for specific editions...
SharkNinja Vacuums Left Vulnerable to Remote Hacking After Delayed Patch
LONDON (July 13, 2026) — A critical security flaw in SharkNinja robotic vacuums allows attackers to seize control of devices across global regions by exploiting an unpatched error in Amazon Web Servic...
Russian Cyber Group Targets Global Users with Trojanized Software Installers
A financially motivated Russian cyber threat actor, tracked under the designation UAT-11795, has launched a widespread campaign deploying Starland Remote Access Trojans (RAT) by compromising legitimat...
Security Researcher Discloses Windows Zero-Day Over Dispute With Microsoft
A security researcher known by the pseudonym Chaotic Eclipse has publicly disclosed a new zero-day exploit targeting fully patched versions of the Windows operating system, escalating a long-standing ...
Zoom Issues Urgent Alert Over Critical Account Takeover Flaw in Windows Clients
SAN FRANCISCO (July 15, 2026) — Video conferencing giant Zoom issued an urgent security advisory on Tuesday warning of a critical vulnerability that could allow attackers to hijack user accounts acros...
Malicious AsyncAPI Packages Target Developer Credentials in Supply Chain Attack
LONDON (July 15, 2026) — A threat actor exploited a misconfigured GitHub Actions workflow to publish five malicious versions of popular AsyncAPI packages on the npm registry, launching a supply-chain ...
CISA Urges Immediate Action as Hackers Exploit Critical SharePoint Flaws
WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent advisory on Monday, July 14, directing organizations to immediately harden their Microsoft SharePoint Ser...
SonicWall Urges Immediate Patching as Critical Zero-Day Attacks Target SMA1000 Appliances
SAN JOSE, Calif. (July 14, 2026) — Network security firm SonicWall issued an urgent advisory on Monday warning that two critical vulnerabilities in its SMA1000 application delivery controllers are bei...
Threat Actor Deploys Nearly 300 Fake GitHub Repositories to Distribute Infostealer Malware
A financially motivated threat actor, likely Russian-speaking, has published nearly 300 fake repositories on the code-sharing platform GitHub designed to impersonate legitimate software and distribute...
Microsoft Issues Record-Breaking Patches for 622 Vulnerabilities Amid Active Directory Exploits
REDMOND, Wash. — Microsoft released a record-breaking batch of security updates on Wednesday to address 622 vulnerabilities across its software portfolio, including two actively exploited zero-day fla...
Microsoft Deploys July 2026 Security Patches for Windows 11 Amid Feature Updates
REDMOND, Wash. (AP) — Microsoft released critical security updates and feature enhancements for its Windows 11 operating system on Thursday morning, addressing vulnerabilities identified in the compan...