Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Cybersecurity News Digest — July 29, 2026

Origin Energy confirms a breach touching roughly 900,000 customer accounts, Termite ransomware affiliate Velvet Tempest is caught staging attacks with ClickFix and a CastleRAT backdoor, an actively exploited Arista VeloCloud Orchestrator zero-day lands in CISA's KEV catalog, AI helps a researcher turn a Linux kernel race condition into a root exploit, and JetBrains patches an unauthenticated RCE in TeamCity before anyone finds it first.

Read source →

Cybersecurity News Digest — July 28, 2026

Coca-Cola confirms the Anubis ransomware gang stole data from its Fairlife dairy unit, RansomHouse's extortion of Japan's largest cold-chain logistics operator ripples into KFC Japan's menu, a Telegram-based backdoor surfaces in attacks on Middle East governments, and a public exploit lands for a pre-auth vBulletin RCE.

Read source →

Cybersecurity News Digest — July 27, 2026

South Korea discloses a ten-month breach of its diplomatic academy's training system, a researcher escapes Claude Cowork's Linux VM to read Mac host files, a phishing link could forge a rogue autonomous agent inside any ChatGPT Workspace, and a race condition in Ubuntu's snap-confine hands local users root.

Read source →

Cybersecurity News Digest — July 26, 2026

SonicWall's SMA1000 zero-days have been under active exploitation since June, a public PoC lets any GitLab contributor run commands as git through a notebook-diff heap bug, a threat actor ran the Hermes AI agent unattended against Thailand's Finance Ministry, and Anubis ransomware gives Coca-Cola's Fairlife until tomorrow before leaking 1TB of stolen data.

Read source →

Cybersecurity News Digest — July 25, 2026

A CISA deadline lands today for a SharePoint RCE attackers are using to steal machine keys that survive patching, a Certighost exploit lets any domain user impersonate a Domain Controller, Golden Chickens resurfaces with four new modular malware families, and Craneware confirms attackers stole data affecting thousands of US hospitals.

Read source →

Cybersecurity News Digest — July 24, 2026

ShinyHunters vishes an Abbott employee into handing over an Entra SSO account and claims tens of millions of patient records, Chaos ransomware's new msaRAT backdoor hides its C2 traffic inside Chrome and Edge, Stadler Rail refuses a $12.3M ransom after a supplier's platform is breached, and a Chrome extension flaw on 329 million browsers let any website read WhatsApp Web chats.

Read source →

Cybersecurity News Digest — July 23, 2026

A public PoC turns a fourth SharePoint RCE into active machine-key theft, a chained WordPress Core bug lets anonymous attackers run code on default installs, Anubis ransomware claims Coca-Cola's Fairlife breach and threatens to leak 1TB of data, and Google ships an AI model that finds, exploits, and patches vulnerabilities on its own.

Read source →

Cybersecurity News Digest — July 22, 2026

A hacker wipes Romania's entire land registry after a failed extortion attempt, an exposed AWS bucket leaks 48,000 car rental bookings, Zimbra patches an unauthenticated command-injection flaw and four XSS bugs, and a researcher nets $78,000 for an IDOR chain in Meta's support platform.

Read source →

Cybersecurity News Digest — July 21, 2026

A ransomware attack halts US production at Coca-Cola's Fairlife dairy unit, ServiceNow's AI Platform gets hit with a pre-auth sandbox-escape RCE days after disclosure, a Russian-speaking actor runs a botnet almost entirely through Gemini CLI, and Qilin ransomware crews ride a GlobalProtect auth bypass into corporate networks.

Read source →

Cybersecurity News Digest — July 20, 2026

Kaspersky catches HelloNet abusing ViPNet's own update channel against Russian government networks, a 13-year-old Daxin rootkit resurfaces in Taiwan next to a pre-login SYSTEM backdoor, EY confirms client tax records stolen via a support-ticket platform, and Ecopetrol blocks encryption but still loses data from 3,300 cloud accounts.

Read source →