Clop Ransomware Pivots to Industrial Software — PTC Windchill and FlexPLM Under Active Attack
Summary The Clop ransomware gang has shifted tactics, now targeting internet-exposed instances of PTC Windchill and FlexPLM by exploiting a critical improper input validation vulnerability (CVE-2026-12569). Windchill is a widely…
FBI/CISA Advisory: Iranian-Affiliated APTs Now Targeting Siemens, Schneider, and Rockwell PLCs Across U.S. Critical Infrastructure
On July 22, 2026, a joint advisory from the FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command (CNMF), and the Department of the Treasury expanded a prior April 2026 warning…
White House Launches ‘Gold Eagle’: AI-Driven Vulnerability Clearinghouse for U.S. Critical Infrastructure
The White House has launched “Gold Eagle,” a new AI-driven cybersecurity vulnerability coordination initiative stemming from President Trump’s Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security,” signed June…
KDDI Zero-Day Breach Exposes 12 Million Email Credentials Across Six Japanese ISPs
Japanese telecommunications giant KDDI has confirmed that a zero-day vulnerability in third-party email platform software was exploited on May 16, 2026, resulting in unauthorized access to approximately 12.23 million email…
Palo Alto GlobalProtect Auth Bypass (CVE-2026-0257) Is Now a Qilin Ransomware Entry Point
A high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS — CVE-2026-0257 — has been confirmed as an active initial access vector for Qilin ransomware affiliates. The flaw affects the…
Microsoft’s July 2026 Patch Tuesday Fixes Record 570+ CVEs — AI Is Fueling a Patch Tsunami
Microsoft’s July 2026 Patch Tuesday is being called the largest in the company’s history, addressing between 569 and 622 Common Vulnerabilities and Exposures (CVEs) depending on the analysis source. The…
Instructure Paid the Ransom — ShinyHunters Leaked the Data Anyway: 275 Million Students Exposed
In what is shaping up to be one of the largest educational data breaches in history, the ShinyHunters hacking group has leaked data belonging to approximately 275 million students and…
OpenAI’s GPT-Red Outperforms Human Hackers at Prompt Injection — 84% vs 13% Success Rate
Summary OpenAI disclosed details of GPT-Red, an internal automated red-teaming model specifically built to find and exploit prompt injection vulnerabilities in other LLMs. Operating via self-play reinforcement learning, GPT-Red autonomously…
FakeGit Campaign: 7,600 Malicious GitHub Repos Deploy SmartLoader + StealC — AI Agents Are the Target
Summary A large-scale malware supply-chain campaign dubbed FakeGit has seeded approximately 7,600 malicious GitHub repositories impersonating popular tools — Gmail, WhatsApp, Databricks, Jenkins, Docker — to spread the SmartLoader dropper,…
RefluXFS (CVE-2026-64600): Nine-Year-Old Linux Kernel Race Condition Grants Root on 16 Million+ Systems
Summary Qualys Threat Research Unit disclosed RefluXFS (CVE-2026-64600), a local privilege escalation vulnerability in the Linux kernel present since version 4.11 (2017) — a nine-year-old race condition in the XFS…
