Security News
Latest Updates

Stay informed with the latest security trends and insights...

Latest Articles

Explore the most recent articles on security topics.

1. Security News – 2026-07-19

Sun Jul 19 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

The Hacker News

Cybersecurity news and insights

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - July 17, 2026

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it.

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests - July 17, 2026

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.

OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta’s Red Team, which reported the denial-of-service bug and named it, published the

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT - July 17, 2026

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens - July 17, 2026

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late.

The intel feed behind that counter

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft - July 17, 2026

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.

Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using

SecurityWeek

Latest cybersecurity news

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint - July 17, 2026

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.

The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive - July 17, 2026

(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up?

The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants - July 17, 2026

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing.

Google has to ship it in the next major release, Android 18, and by 1 August 2027 at

SecurityWeek

Latest cybersecurity news

Beacon Security Raises $13 Million for Security Data Platform - July 17, 2026

The startup helps organizations detect, hunt, and protect their assets across environments at machine speed.

The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

Details of Alan Turing’s Voice Encryption System - July 17, 2026

Really interesting piece of cryptographic history:

In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away...

SecurityWeek

Latest cybersecurity news

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei - July 17, 2026

The company disconnected its systems on July 13 and is starting to gradually restore operations.

The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files - July 17, 2026

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.

It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the

SecurityWeek

Latest cybersecurity news

Risk Ledger Raises $32 Million in Series B Funding - July 17, 2026

The British firm has built a collaborative platform to help organizations address supply chain security risks.

The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.

Fresh SharePoint Vulnerability Exploited Soon After Disclosure - July 17, 2026

The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.

The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack - July 17, 2026

The company has yet to determine the full scope, nature, and impact of the incident.

The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek.

Legacy Systems, Real-World Impacts: The Reality of OT Security - July 16, 2026

Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts.

The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

Protecting Privacy in an AI Era - July 16, 2026

Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.

Paper.

SecurityWeek

Latest cybersecurity news

Two Scattered Spider Hackers Sentenced to Jail in UK - July 16, 2026

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).

The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek.

View All Security News

Upcoming Events

Check out the upcoming security conferences and webinars.

Security Tools

Discover the latest tools and resources for enhancing security.