Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-20 17:00 PDT
- Estée Lauder discloses data breach via Oracle E-Business flaw
BleepingComputer • 2026-07-20 15:39 • www.bleepingcomputer.com
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]
https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/ - SonicWall SMA1000 flaws exploited as zero-days to push custom malware
BleepingComputer • 2026-07-20 15:23 • www.bleepingcomputer.com
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […]
https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/ - Hackers steal $23.7 million in crypto from Ostium in off-chain attack
BleepingComputer • 2026-07-20 15:22 • www.bleepingcomputer.com
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […]
https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/ - Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
BleepingComputer • 2026-07-20 14:14 • www.bleepingcomputer.com
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. […]
https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/ - JadePuffer agentic attacks now target AI model data with ransomware
BleepingComputer • 2026-07-20 14:08 • www.bleepingcomputer.com
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. […]
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/ - WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
SANS ISC Diary (full) • 2026-07-20 11:41 • isc.sans.eduLast week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
The Hacker News • 2026-07-20 11:23 • thehackernews.com
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.“FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
