Categories Breaking News

Breaking News – Cyber Threats – 2026-07-21 03:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-21 03:00 PDT

  • Microsoft shares manual fix for WSUS sync delays and timeouts
    BleepingComputer • 2026-07-21 02:05 • www.bleepingcomputer.com
    Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […]
    https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeouts/
  • WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
    The Hacker News • 2026-07-21 01:59 • thehackernews.com
    Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

    The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

    “By the early hours of Saturday morning (UTC), successful exploitation was already well
    https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html

  • New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
    Securelist • 2026-07-21 01:40 • securelist.com
    Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
    https://securelist.com/project-cav3rn-cyberespionage-framework-using-outlook-and-dns/120757/
  • Windows LegacyHive zero-day flaw gets free, unofficial patches
    BleepingComputer • 2026-07-21 01:06 • www.bleepingcomputer.com
    Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […]
    https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
  • New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
    The Hacker News • 2026-07-21 00:34 • thehackernews.com
    Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

    The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

    The entry
    https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html

  • Weekly Update 513: Clauding The Home Network
    Troy Hunt • 2026-07-21 00:30 • www.troyhunt.com

    I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is – if ever there was an actual value proposition for AI it's taking lots of noise and

    https://www.troyhunt.com/weekly-update-513/

  • 177: National Public Data
    Darknet Diaries • 2026-07-21 00:00 • darknetdiaries.com

    This is the story of the hacker known as “USDoD”. When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.

    Sponsors

    Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploi…
    https://darknetdiaries.com/episode/177/

  • Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
    The Hacker News • 2026-07-20 23:29 • thehackernews.com
    Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.

    In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.

    Patches for the flaw were
    https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like