AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

21/07/2026 0 Comments 0 tags

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

21/07/2026 0 Comments 0 tags

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

21/07/2026 0 Comments 0 tags

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

21/07/2026 0 Comments 0 tags

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

21/07/2026 0 Comments 0 tags

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will

N-day is Becoming N-Hour. Patching Faster Won’t Save You.

21/07/2026 0 Comments 0 tags

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

21/07/2026 0 Comments 0 tags

A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

21/07/2026 0 Comments 0 tags

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws,

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

21/07/2026 0 Comments 0 tags

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

21/07/2026 0 Comments 0 tags

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said