Categories Breaking News

Breaking News – Cyber Threats – 2026-07-20 17:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-20 17:00 PDT

  • Estée Lauder discloses data breach via Oracle E-Business flaw
    BleepingComputer • 2026-07-20 15:39 • www.bleepingcomputer.com
    Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]
    https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
  • SonicWall SMA1000 flaws exploited as zero-days to push custom malware
    BleepingComputer • 2026-07-20 15:23 • www.bleepingcomputer.com
    Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […]
    https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
  • Hackers steal $23.7 million in crypto from Ostium in off-chain attack
    BleepingComputer • 2026-07-20 15:22 • www.bleepingcomputer.com
    The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […]
    https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/
  • Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
    BleepingComputer • 2026-07-20 14:14 • www.bleepingcomputer.com
    Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. […]
    https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
  • JadePuffer agentic attacks now target AI model data with ransomware
    BleepingComputer • 2026-07-20 14:08 • www.bleepingcomputer.com
    The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. […]
    https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
  • WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
    SANS ISC Diary (full) • 2026-07-20 11:41 • isc.sans.edu

    Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.


    https://isc.sans.edu/diary/rss/33168

  • FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
    The Hacker News • 2026-07-20 11:23 • thehackernews.com
    Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.

    “FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
    https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like