Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Cybersecurity News Digest — July 15, 2026

Microsoft's record-breaking Patch Tuesday closes two zero-days already under attack, a 15-year-old Linux kernel bug hands out root, SonicWall SMA appliances get chained in the wild, and Japan's largest taxi operator goes dark.

Read source →

Cybersecurity News Digest — July 14, 2026

A joint advisory on Russian FSB router hacking, a compromised npm package dropping a Rust infostealer, Progress Software's emergency ShareFile shutdown, and CISA confirming ransomware gangs are exploiting a Microsoft Defender flaw.

Read source →

Cybersecurity News Digest — July 13, 2026

This week's cybersecurity roundup: Russian hackers hijacking doorbell cameras to track NATO weapons shipments, a Linux kernel root flaw hitting Android, a new Entra passkey vishing campaign, and prompt injection hidden in images to fool AI code reviewers.

Read source →

Operation First Light 2026: 5,811 Arrests and $293M Seized in Global Fraud Crackdown

Threat Intelligence Regulations Identity & Access

An INTERPOL-coordinated operation across 97 countries closed over 23,000 fraud cases, froze 31,014 bank accounts, and identified 142,000+ victims of social engineering scams.

Why it matters: Scale like this tells you social engineering isn't a fringe risk — it's an industrialized criminal supply chain with the same maturity as any other cybercrime market. If your security awareness training still frames phishing and BEC as isolated incidents rather than organized fraud, this is a good prompt to update it.
Read source →

Microsoft Patches 'RoguePlanet' Defender Flaw That Grants SYSTEM Privileges

Vulnerability AWS Tools

CVE-2026-50656, a race condition in the Microsoft Malware Protection Engine, let local attackers spawn a SYSTEM-level shell on fully patched Windows hosts. Microsoft has shipped a fix.

Why it matters: The irony here is the attack surface: your endpoint protection engine itself. Confirm the Malware Protection Engine has auto-updated to 1.1.26060.3008 or later across your fleet — this doesn't wait for a normal patch cycle, but it's worth verifying rather than assuming.
Read source →

GodDamn Ransomware Uses Signed PoisonX Driver to Blind Endpoint Defenses

Incident Response Vulnerability Threat Intelligence

A ransomware family tied to the Hyadina group (rebranded from Beast) uses a Microsoft-signed malicious kernel driver, AnyDesk, and PsExec to disable security tooling before encrypting data.

Why it matters: A signed kernel driver bypassing your EDR is a detection-layer problem, not a patching problem. Make sure your monitoring flags unexpected kernel driver loads and known dual-use remote access tools like AnyDesk and PsExec running outside of change-managed maintenance windows.
Read source →

Ubiquiti Patches Maximum-Severity UniFi OS Command Injection Flaw

Vulnerability Tools

Ubiquiti shipped fixes for seven critical UniFi OS vulnerabilities, including CVE-2026-50746, an unauthenticated CVSS 10.0 command injection bug reachable by any device on the same network segment.

Why it matters: Confirm your UniFi Connect, Access, Protect, Talk, and OS deployments are on the patched builds — CVE-2026-50746 needs no authentication and no more than network adjacency, which describes most guest or IoT VLANs that share a segment with management infrastructure.
Read source →

JadePuffer: First Documented Ransomware Attack Run End-to-End by an AI Agent

Threat Intelligence Incident Response Vulnerability

Sysdig researchers found JadePuffer, a ransomware operation where an autonomous LLM agent handled recon, credential theft, lateral movement, and encryption without a human operator.

Why it matters: The individual steps here aren't new — the automation is. If your detection rules assume a human operator's pacing and mistakes, this incident is a signal to test them against faster, self-correcting behavior, and to prioritize patching internet-facing AI tooling like Langflow before attackers' agents get there first.
Read source →