Categories Breaking News

Breaking News – Cyber Threats – 2026-07-20 03:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-20 03:00 PDT

  • Critical ServiceNow code execution flaw now exploited in attacks
    BleepingComputer • 2026-07-20 02:29 • www.bleepingcomputer.com
    Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […]
    https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
  • New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
    The Hacker News • 2026-07-20 02:10 • thehackernews.com
    Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.

    The overflow lets an attacker “execute code in the context of the current process,” per the
    https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html

  • Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
    The Hacker News • 2026-07-20 02:07 • thehackernews.com
    A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.

    The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential
    https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html

  • World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
    The Hacker News • 2026-07-19 22:27 • thehackernews.com
    In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.

    The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

    “We identified unauthorized access to a limited set of internal datasets and to several credentials used by
    https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html

  • SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
    The Hacker News • 2026-07-19 22:15 • thehackernews.com
    Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

    The rogue gems are listed below –

    git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026
    Dendreo (versions 1.1.3, 1.1.4) –
    https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like