Security News
Latest Updates

Stay informed with the latest security trends and insights...

Latest Articles

Explore the most recent articles on security topics.

1. Security News – 2026-07-16

Thu Jul 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

SecurityWeek

Latest cybersecurity news

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day - July 16, 2026

The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability.

The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day  appeared first on SecurityWeek.

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities - July 16, 2026

The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.

The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development - July 15, 2026

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results.

“While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps - July 15, 2026

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase.

On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and

SecurityWeek

Latest cybersecurity news

Unpatched Cursor Vulnerability Exposes Users to Code Execution - July 15, 2026

An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.

The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - July 15, 2026

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws - July 15, 2026

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.

The vulnerabilities are listed below -

CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component

“We are aware that exploit code for this is public, however we are not aware of

SecurityWeek

Latest cybersecurity news

Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.

The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. - July 15, 2026

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.

Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday - July 15, 2026

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.

It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.

“The PoC requires

New Webinar: Closing the Approval Gap in AI-Era Ad Tech - July 15, 2026

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages.

This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first.

The Reality of the Approval Gap

It’s a pattern every

Schneier on Security

Security news and analysis by Bruce Schneier

A Video Screen That Is Also a Camera - July 15, 2026

Amazing:

Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.

We are one step closer to 1984 technology:

The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment...

SecurityWeek

Latest cybersecurity news

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - July 15, 2026

A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.

The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek.

White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative - July 15, 2026

The new program stems from an AI-focused Executive Order signed by President Trump on June 2.

The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek.

Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption - July 15, 2026

The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it.

The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware - July 15, 2026

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity.

The affected packages are listed below -

@asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1)

“The

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands - July 15, 2026

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.

The vulnerabilities are listed below -

CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack - July 14, 2026

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s previous high of around 200.

Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are

Schneier on Security

Security news and analysis by Bruce Schneier

Vulnerability in FIFA’s Network - July 14, 2026

FIFA’s network was vulnerable to anyone with even minimal access.

AI Data Centers and the Concentration of Wealth - July 13, 2026

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for constructive debate on any issue, and agree that communities need to evaluate whether any economic benefits these data centers bring is worth their costs. Still, we worry that a focus on data centers obscures the larger impacts of AI on people’s lives: the concentration of power of AI companies, and their widespread political and financial influence...

Trail of Bits Blog

Security research and insights from Trail of Bits

Rust-proof your code with our new Testing Handbook chapter - July 13, 2026

We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems.

fn
main()
{(|f:&dyn
Fn(u128)->Box<
dyn Iterator<Item=
char>+'static>|f(*[&(
0x7B736D70683F73u128<<64|
0x7A6A6D7C3F7A667D),&(0x7B736Du128
<<64|0x70683F7073737A77)][((std::hint::
black_box(0.0f64)/0.0).to_bits()>>63)as usize])
.for_each(|c|print!("{c}")))(Box::leak(Box::new(|n:
u128|Box::new(std::iter::successors(Some(n),|&n|Some(n>>8)
).take_while(|&n|n>0).map(|n|((n as u8)^0x1F)as char))as _)))}

What’s in the chapter

The chapter starts with a security overview of what Rust’s guarantees do and don’t cover, including underappreciated issues like unwind safety, nondeterminism, and arithmetic errors. This leads into an overview of dynamic analysis, which covers a range of boosters for unit tests, how to use Miri to detect undefined behavior, property testing with proptest, coverage measurement, and mutation testing. The static analysis section then covers Clippy in depth, including a list of our favorite lints.

Beyond tooling, the chapter also covers what we’ve learned from auditing Rust codebases directly. Our gotchas and footguns checklist is a great reference for manual code reviews, and will help you find subtle issues like a & b == c having different operator precedence than in C. The memory zeroization section offers three solutions to the tricky problem of guaranteeing that secrets are erased from memory.

Finally, the specialized testing sections cover tools like Kani (a model checker), and the supply chain section covers the full toolchain for vetting dependencies.

Still oxidizing

We’ve also released rust-review, a Claude Code plugin for automated Rust security reviews. Co-built with Aptos Labs, it targets over a dozen bug classes, from memory safety and concurrency hazards to FFI pitfalls and async cancellation issues. It’s a fast way to catch security issues in a Rust codebase before they make it to audit.

Our goal is to keep the handbook current as the Rust ecosystem evolves. If your favorite tool or gotcha isn’t covered, submit a PR. And if you need help securing your Rust systems, contact us.

View All Security News

Upcoming Events

Check out the upcoming security conferences and webinars.

Security Tools

Discover the latest tools and resources for enhancing security.