ChocoPoC RAT Targets Security Researchers via Fake CVE PoC Repos on GitHub
Summary Security researchers have identified a new data-stealing trojan named ChocoPoC being distributed through a campaign specifically targeting vulnerability researchers, red teamers, and purple team operators. The malware is concealed…
AsyncAPI npm Supply Chain Attack: M-RED-TEAM Payload Hidden in Four Malicious Packages via GitHub Actions Token Theft
Summary On July 14, 2026, security researchers at Wiz and Microsoft disclosed a coordinated supply chain attack against the @asyncapi npm organization — one of the most widely used open…
jscrambler Supply-Chain Attack: Poisoned npm Package v8.14.0 Steals Cloud Credentials and Browser Sessions
Summary Security researchers disclosed a confirmed supply-chain attack against jscrambler, a widely used JavaScript obfuscation and protection library, this week. Version 8.14.0 of the jscrambler npm package was compromised and…
White House Launches GOLD EAGLE: AI-Powered Federal Cyber Defense Initiative for Vulnerability Coordination at Machine Speed
Summary The White House announced the GOLD EAGLE initiative this week, a new operational model for federal cyber defense that leverages advanced AI capabilities for what the administration is calling…
New Windows Zero-Day PoC Drops Post-Patch Tuesday: LegacyHive User Profile Service Exploit Works on All Supported Versions
Summary Within days of Microsoft’s record July Patch Tuesday, a researcher publicly released a proof-of-concept exploit for a new Windows zero-day vulnerability in the User Profile Service, dubbed LegacyHive. The…
DuneSlide: Zero-Click Prompt Injection in Cursor AI Code Editor Achieves OS-Level RCE — Unpatched for Six Months
Summary Security researchers publicly disclosed a critical zero-day vulnerability in the Cursor AI code editor this week, dubbed DuneSlide, that enables zero-click prompt injection leading to full OS-level remote code…
Deutsche Bank Confirms Third-Party Breach as Unsafe Ransomware Group Claims Employee Data Theft
Summary Deutsche Bank confirmed this week that it suffered a cybersecurity incident involving a third-party service provider, after the ransomware group known as Unsafe claimed responsibility and began publishing what…
SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVSS 10.0 SSRF and Code Injection Hit Remote Access Appliances
Summary SonicWall issued an urgent security advisory this week warning customers that two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances are being actively exploited in the…
Microsoft July Patch Tuesday: Record 570+ Flaws Fixed, Two Zero-Days Actively Exploited in AD FS and SharePoint
Summary Microsoft’s July 2026 Patch Tuesday is the largest in the company’s history, addressing between 570 and 622 security vulnerabilities across Windows and its broader software ecosystem — nearly triple…
Google, Microsoft, Salesforce, and Snowflake Form Alliance to Challenge Anthropic’s MCP Standard
Summary Google, Microsoft, Salesforce, Snowflake, and ServiceNow announced a formal alliance on July 13, 2026, to develop and promote a shared backend protocol standard for enterprise AI agent connectivity —…
