SharePoint Critical Zero-Day (CVE-2026-50522) Actively Exploited — Attackers Steal Machine Keys for Persistent Access
Summary A critical deserialization vulnerability in Microsoft Office SharePoint, tracked as CVE-2026-50522 (CVSS 9.8), is under active exploitation. Threat actors chain this flaw with other SharePoint vulnerabilities to gain unauthorized…
SharePoint Critical Zero-Day (CVE-2026-50522) Actively Exploited — Attackers Steal Machine Keys for Persistent Access
Summary A critical deserialization vulnerability in Microsoft Office SharePoint, tracked as CVE-2026-50522 (CVSS 9.8), is under active exploitation in the wild. Threat actors are chaining this flaw with other SharePoint…
Anthropic Limits Access to AI Model That Finds Security Flaws, Citing Hackers Misuse Risk
Summary Anthropic has restricted access to an AI model designed to identify security vulnerabilities, citing concerns that the model’s capabilities could be misused by hackers to find and exploit flaws…
Accenture Confirms Breach: 35GB of Source Code, SSH Keys, and Azure Tokens Stolen
Summary Global IT services giant Accenture has confirmed a security breach after a threat actor known as “888” offered stolen data for sale. The threat actor claims to have exfiltrated…
Pentagon Suspends CMMC Phase 2, Launches Broad Review of Defense Contractor Cybersecurity Certification
Summary On July 13, 2026, the U.S. Department of War announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) assessment requirements, which had been scheduled…
Anthropic Suspends Claude Fable 5 Access After U.S. Government Export Control Over Jailbreak Concerns
Summary Anthropic launched Claude Fable 5, billed as its most capable publicly available model, but access was subsequently suspended following a U.S. government export control directive. The suspension was triggered…
Hugging Face Breached by Autonomous AI Agent — First Known AI-Driven Attack on ML Platform Infrastructure
Summary Hugging Face disclosed a security incident in July 2026 that marks a historic milestone in cybersecurity: the first known intrusion into production infrastructure driven entirely by an autonomous AI…
EY Breach: Attackers Spend 15 Days Inside Helpdesk Platform, Steal Client Tax Files
Summary Ernst & Young (EY) has disclosed a security breach in which threat actors compromised a third-party IT helpdesk platform used by EY’s tax practice. The attackers operated undetected for…
Instructure Canvas Breach: 275 Million Users Affected After ShinyHunters Exports Student Data
Summary The edtech giant Instructure, operator of the Canvas Learning Management System used by thousands of schools worldwide, has been breached by the hacking collective known as ShinyHunters. The breach…
CVE-2026-56188: Potentially Wormable CVSS 9.8 Windows Server Network Driver RCE — ‘More Likely’ to Be Exploited, Microsoft Warns
Among the 622 flaws patched in Microsoft’s July 2026 Patch Tuesday, security researchers have flagged CVE-2026-56188 as deserving special urgency. This critical remote code execution vulnerability in the Windows Server…
