Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-21 13:00 PDT
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
BleepingComputer • 2026-07-21 11:50 • www.bleepingcomputer.com
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. […]
https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/ - Critical wp2shell WordPress flaws exploited to install webshells
BleepingComputer • 2026-07-21 09:41 • www.bleepingcomputer.com
Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. […]
https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/ - AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
The Hacker News • 2026-07-21 09:06 • thehackernews.com
Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it.Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been
https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html - Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
The Hacker News • 2026-07-21 08:09 • thehackernews.com
Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently.According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot
https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html - Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
The Hacker News • 2026-07-21 07:57 • thehackernews.com
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE
https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html - Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
The Hacker News • 2026-07-21 07:04 • thehackernews.com
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html - Closing the Identity Gaps in Critical Infrastructure Security
BleepingComputer • 2026-07-21 07:00 • www.bleepingcomputer.com
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. […]
https://www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
