A previously unknown threat actor, tracked as UTA0533, has been linked to attacks targeting SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, using two zero-day vulnerabilities before they were publicly disclosed. The attackers exploited two flaws (CVE-2026-15409 and CVE-2026-15410) to gain remote command execution and take over vulnerable devices. SonicWall released security patches for both vulnerabilities earlier this month.
The US cybersecurity agency CISA has warned that a Russian state-sponsored hacking group, tracked as Laundry Bear and Void Blizzard, is targeting organizations that use Zimbra Collaboration email servers. The attackers use phishing and a patched Zimbra security flaw (CVE-2025-66376) to steal emails, passwords, contact lists, and two-factor authentication (2FA) tokens from unpatched systems.
Attackers are actively exploiting a critical ServiceNow AI Platform vulnerability (CVE-2026-6875). ServiceNow patched hosted instances in April and released security updates for self-hosted instances on July 13.
Also, reports emerged that a security flaw in the open-source platform Windmill is being actively exploited. The vulnerability (CVE-2026-29059) lets attackers access files without authentication and could also allow them to run malicious code on affected systems.
Yet another issue that is being actively exploited is Microsoft SharePoint vulnerability (CVE-2026-50522), which threat actors use to steal machine keys and keep access to compromised servers even after security patches are installed.
Check Point Software has fixed a critical zero-day vulnerability (CVE-2026-16232) in its SmartConsole admin panel that was being actively exploited. The flaw lets attackers bypass authentication and gain administrator access without logging in if the management server is exposed to the internet and Trusted Clients are not restricted.
The Qilin ransomware gang is exploiting a critical security flaw in Palo Alto Networks' PAN-OS GlobalProtect software to break into company networks and deploy ransomware. The vulnerability, tracked as CVE-2026-0257, was fixed by Palo Alto Networks on May 13.
The Clop/Cl0p ransomware gang has been observed targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. The attackers exploited CVE-2026-12569, a critical improper input validation flaw, which allows attackers to execute arbitrary code. Threat actors have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms.
Russia-linked UAC-0099 group has changed its attack techniques and is now using new malware called Lunchpoke and Burnybear, as well as an updated version of Matchboil. The threat actor has also been observed using legitimate Notepad++ software to hide malicious code.
Hackers have had access to South Korea's diplomatic training system for about nine months, pilfering personal data belonging to former and current employees of the Ministry of Foreign Affairs. The stolen information may include users' IDs, names, email addresses, and encrypted passwords. The ministry said sensitive data, such as contact details and personal photos, was not affected.
The Iranian state-backed threat actor tracked as APT42 has evolved its tactics, adopting AI-assisted phishing and employing an upgraded, fileless version of the Tamecat backdoor. APT42 incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. The campaigns mainly target defense officials, government personnel, and geopolitical experts.
The US authorities have warned that Iranian state-backed hackers are targeting internet-connected control systems used by US water and energy providers. The updated guidance includes new detection techniques and warns that multiple PLC brands, including Rockwell, Schneider Electric, and Siemens, are being targeted.
North Korean hacking group Kimsuky (APT43) targeted South Korean collaboration software vendors in 2025 and early 2026 before using the breaches to access the vendors' customers. The attackers exploited a mail server vulnerability in one case and used social engineering to infect an employee's computer in another.
Zscaler ThreatLabz spotted a new campaign targeting government organizations in the Middle East. The attackers, believed to be based in East Asia, use a malicious ISO file that exploits a trusted ASUSTek application to install malware. The attack delivers three new malware families called TELESHIM, MIXEDKEY, and BINDCLOAK.
Sygnia released a report on a cloud intrusion where an attacker gained unauthorized access to an AWS environment and moved across cloud services, applications, source control, CI/CD, and runtime systems. The attack used common techniques rather than new malware or zero-day exploits, taking advantage of weaknesses in secrets management, identity controls, deployment processes, and cloud permissions.
Researchers in China have devised a new technique called Bit2Watt, that demonstrates how AI and GPU workloads in data centers could be used to disrupt nearby power grids. The study describes a scenario where an attacker pretends to be a normal cloud customer and runs specially designed GPU workloads. Instead of targeting computer systems directly, the workloads decrease or increase power consumption at the same time, putting stress on data centers and the electrical grid.
OpenAI has taken responsibility for the breach of the AI platform Hugging Face. The company said several of its AI models, including GPT-5.6 Sol and an unreleased model, escaped their sandbox during a cybersecurity evaluation and accessed Hugging Face's servers. OpenAI is now working with Hugging Face to investigate the incident.
Security researchers have linked the April 2026 DigiCert security incident to a threat group called CylindricalCanine, a subgroup of the Chinese cybercrime organization tracked as GoldenEyeDog. The group is known for targeting gambling, gaming, and finance organizations with malware delivered through fake websites and phishing campaigns.
Cisco Talos discovered a new Rust-based remote access trojan (RAT) called msaRAT, linked to the Chaos ransomware group. The malware uses the Chrome DevTools Protocol (CDP), a browser debugging feature, to communicate with its command-and-control (C&C) server.
Authorities in Germany and the US have shut down the main infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform used by cybercriminals worldwide. During the operation, law enforcement seized more than 200 servers. The platform's developer was arrested in Indonesia.
The FBI has arrested a 21-year-old Florida man accused of uploading fake video games to Steam that installed malware on players' computers. According to US prosecutors, Zyaire Wilkins and several unnamed accomplices published fake games such as BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi over the past two years. The malware was designed to steal passwords, personal data, and cryptocurrency from victims.
A US court has sentenced Chinedu Opute, an American national, to six years in prison for helping run an email fraud scheme that stole over $1.4 million from businesses. He and his co-conspirators hacked business email accounts, pretended to be trusted vendors, and tricked companies into sending payments to bank accounts they controlled. Opute set up the bank accounts used to receive and move the stolen money.
Pakistan's NCCIA reportedly arrested 12 members of a cybercrime gang accused of hacking the contact numbers and data of foreign embassies, including Saudi Arabia, Germany, and Italy. The group allegedly ran fake embassy websites, redirected calls, and used fake appointment letters to scam victims. Police recovered mobile phones, digital evidence, and other items during the raids.