Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-22 13:00 PDT
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
The Hacker News • 2026-07-22 11:07 • thehackernews.com
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as
https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html - Rondo Meets Geoserver, (Wed, Jul 22nd)
SANS ISC Diary (full) • 2026-07-22 10:35 • isc.sans.eduThis isn't a new attack, but something I saw “pop-up” in our logs this week:
- Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
BleepingComputer • 2026-07-22 09:59 • www.bleepingcomputer.com
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […]
https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/ - How enterprise GenAI can amplify ransomware risk — and how to contain it
BleepingComputer • 2026-07-22 08:30 • www.bleepingcomputer.com
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. […]
https://www.bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it/ - Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
The Hacker News • 2026-07-22 08:01 • thehackernews.com
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability
https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html - New InfraTrust report reveals infrastructure flaws admins should patch first
BleepingComputer • 2026-07-22 07:15 • www.bleepingcomputer.com
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. […]
https://www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
