Apple Sues OpenAI for Trade Secret Theft, Citing 400+ Former Employees and Coordinated Hardware IP Extraction
Apple filed a federal lawsuit against OpenAI on July 10, 2026 in the U.S. District Court for the Northern District of California, accusing the AI company of systematic trade secret…
CISA Adds Two CVSS 10.0 Joomla Zero-Days to KEV — Mass Exploitation Underway Since June
CISA added two maximum-severity (CVSS 10.0) zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 13, 2026: CVE-2026-48939 in the iCagenda extension for Joomla, and CVE-2026-56291 in the…
JADEPUFFER: The First Fully Autonomous AI-Agent Ransomware Operation Is Here
Sysdig’s Threat Research Team has documented JADEPUFFER — the first fully autonomous, end-to-end AI-agent ransomware operation ever recorded. Unlike traditional ransomware that requires a human operator calling the shots, JADEPUFFER…
Microsoft Patches RoguePlanet Defender Zero-Day (CVE-2026-50656) and Warns: Patch Windows in Under 3 Days as AI Compresses Exploit Windows
Microsoft patched “RoguePlanet” (CVE-2026-50656), a zero-day privilege escalation vulnerability in Microsoft Defender, on July 9, 2026. The flaw exploits a race condition in Defender’s threat remediation engine to grant attackers…
Q2 2026 Ransomware Report: 43% Year-Over-Year Surge, 91 Active Groups, and Qilin’s Unbroken Dominance
GuidePoint Security’s Q2 2026 Ransomware and Cyber Threat Insights Report reveals the ransomware ecosystem reached record activity levels in the second quarter, with threat actors claiming 2,279 victims — a…
CISA Adds Langflow AI Framework Bug (CVE-2026-55255) to KEV — Authorization Bypass Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255, an authorization bypass vulnerability in Langflow, to its Known Exploited Vulnerabilities (KEV) Catalog in early July 2026, alongside path traversal…
Ubiquiti Discloses Seven Critical UniFi Flaws — CVSS 10.0 Unauthenticated RCE Threatens 100,000 Exposed Endpoints
Ubiquiti disclosed seven critical vulnerabilities across its UniFi product line in early July 2026, including a maximum-severity flaw (CVSS 10.0) that allows unauthenticated network attackers to execute arbitrary operating system…
WP-SHELLSTORM: China-Linked Webshell Operation Targets 1.4 Million Sites — Exposed Operator Server Reveals Full Playbook
Security researchers at SOCRadar exposed a sophisticated, China-linked web application backdoor operation dubbed WP-SHELLSTORM in early July 2026. The operation, attributed to a financially motivated Webshell Access Brokerage Operation (WABO),…
Meta Launches Muse Spark 1.1 — First Paid AI Model with 1M-Token Context Window Takes Aim at OpenAI and Anthropic
Meta Superintelligence Labs launched Muse Spark 1.1 on July 9, 2026 — its first commercially priced AI model and a direct shot at OpenAI and Anthropic’s enterprise products. The multimodal…
Cisco SD-WAN Zero-Day Exploitation Campaign Hit Government and Critical Infrastructure for Months Before Patch
A monthslong exploitation campaign targeting Cisco Catalyst SD-WAN infrastructure has compromised government agencies and critical infrastructure operators worldwide, according to reporting from Cisco Talos, Mandiant, and multiple national cybersecurity authorities.…
