Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a…
More alerts are making your team slower, and an outcome-based SOC fixes that
In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware.…
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager…
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production…
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: WP2Shell…
A forensic tool for backdoored code completions in AI assistants
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some…
Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
Hugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 16, 2026, noting that…
Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the…
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix…
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as…
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, July 20th, 2026…
WordPress RCE, New Windows 0-day and Coca-Cola’s Fairline ransomed
New Windows zero-day, Coca-Cola’s Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from “Nightmare Eclipse” called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be…
IT Security News Hourly Summary 2026-07-20 03h : 1 posts
1 posts were published in the last hour 0:34 : Paidwork – 23,272,765 breached accounts
Paidwork – 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M…
IT Security News Hourly Summary 2026-07-20 00h : 3 posts
3 posts were published in the last hour 21:58 : IT Security News Weekly Summary 29 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
IT Security News Weekly Summary 29
210 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the…
IT Security News Daily Summary 2026-07-19
21 posts were published in the last hour 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the risk radius 16:34 : Hidden Wi‑Fi Killers: Everyday…
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3…
Connecting AI agents to outside services explodes the risk radius
Connect all the things and watch what happens This article has been indexed from www.theregister.com – Articles Read the original article: Connecting AI agents to outside services explodes the risk radius
Hidden Wi‑Fi Killers: Everyday Things Quietly Ruining Your Home Internet
Many everyday objects can quietly wreck your Wi‑Fi, and understanding them is the first step to a more stable home network. From kitchen gadgets to building materials, the invisible radio waves carrying your data are constantly competing with physical…
Helix Data Extortion Group Targets Microsoft SharePoint Using Vishing and MFA Abuse
Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse…
Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in…
IT Security News Hourly Summary 2026-07-19 18h : 3 posts
3 posts were published in the last hour 15:34 : Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION 15:34 : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106 15:6 : Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL…