CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day
CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day CVE-2025-66376 is a stored cross-site scripting vulnerability in the Classic UI of Zimbra Collaboration Suite, creating a path to mailbox theft and...
SharedRoot: Sandbox Escape in Claude Cowork
SharedRoot: Sandbox Escape in Claude Cowork SharedRoot is the name researchers gave to a sandbox-escape chain affecting the local execution mode of Claude Cowork on macOS. The chain uses CVE-2026-4633...
Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure
Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure On July 22, 2026, seven US government agencies updated joint Cybersecurity Advisory AA26-097A, first published in April, warning that ...
Oracle July 2026 CPU: 1,449 Patches, 10 Score Max
Oracle July 2026 CPU: 1,449 Patches, 10 Score Max Oracle July 2026 Critical Patch Update ships 1,449 patches covering 1,434 CVEs across 334 products in 32 product families, making it the largest quart...
Adobe Acrobat WhatsApp Flaw “HermeticReader”
Adobe Acrobat WhatsApp Flaw “HermeticReader” Adobe and WhatsApp have rolled out a new way to handle PDF files without ever leaving a chat, and the timing puts a spotlight on a vulnerability that Adobe...
WhatsApp Usernames Explained: Privacy Gains and Scam Risks
WhatsApp Usernames Explained: Privacy Gains and Scam Risks How WhatsApp’s shift from phone numbers to usernames changes privacy for users, and the brand and executive impersonation surface it opens fo...
CVE-2026-50522 PoC Fuels SharePoint Attacks
CVE-2026-50522 PoC Fuels SharePoint Attacks Attackers are exploiting CVE-2026-50522, a critical Microsoft SharePoint Server vulnerability, after public proof-of-concept (PoC) exploit code became avail...
OpenAI Models Hacked Hugging Face During a Cyber Test
OpenAI Models Hacked Hugging Face During a Cyber Test [30.07.2026] Update: The Scope Keeps Growing During an internal cybersecurity benchmark in July 2026, OpenAI’s GPT-5.6 Sol and a more capable unre...
CVE-2026-6875 Hits ServiceNow AI Platform
CVE-2026-6875 Hits ServiceNow AI Platform Attackers are reportedly exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform. The flaw can allow an unauthenti...
SonicWall SMA Flaws Lead to KNUCKLEBALL Malware
SonicWall SMA Flaws Lead to KNUCKLEBALL Malware SonicWall SMA 1000 appliances were compromised in a zero-day campaign involving custom malware, root-level access, credential gathering, and attempts to...
Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost a...
Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North...
7-Zip CVE-2026-14266 RCE Risk Explained
7-Zip CVE-2026-14266 RCE Risk Explained CVE-2026-14266 is a heap-based buffer overflow in 7-Zip’s XZ decompression logic. If a user opens or extracts specially crafted compressed content with an affec...
WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs
WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs Updated July 20, 2026: In-the-wild exploitation confirmed. Public proof-of-concept exploits for the full chain are now circulatin...
FIFA World Cup 2026 Fraud Campaigns
FIFA World Cup 2026 Fraud Campaigns Between April and July 2026, the SOCRadar Threat Research Unit (STRU) tracked the fraud ecosystem built around the FIFA World Cup 2026 spanning counterfeit merchand...
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n AI and workflow automation platforms can connect identities directly to actions across email, cloud services, databases, and other business sys...
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days Microsoft released its July 2026 Patch Tuesday security updates on July 14, 2026, addressing 622 CVEs – one of the largest single releases on ...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-447...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-44747 On July 14, 2026, SAP released its monthly security updates, delivering 16 new Security Notes and one GitHub security advisory,...
How HalluSquatting Could Fuel Agentic Botnets
How HalluSquatting Could Fuel Agentic Botnets AI agents can make software development and automation faster, but they can also introduce a new supply chain risk. HalluSquatting, also known as adversar...
MDASH and AI Reshape Windows Patching
MDASH and AI Reshape Windows Patching Microsoft is planning to bring AI deeper into Windows vulnerability management through tools such as MDASH, an internal system designed to identify and validate s...
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
How WP-SHELLSTORM Exposed 1.4M WordPress Sites The SOCRadar Threat Intelligence Team traces an exposed directory back to a Chinese-linked cybercrime operation and details findings from the investigati...
