ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Today’s signal The Hacker News recently reported ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link. Published context: July 24, 2026. Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since b ...

July 24, 2026 · 3 min · David Gomez

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Today’s signal The Hacker News recently reported Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs. Published context: July 22, 2026. Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10 ...

July 23, 2026 · 3 min · David Gomez

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Today’s signal The Hacker News recently reported Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers. Published context: July 23, 2026. Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, din ...

July 23, 2026 · 3 min · David Gomez

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Today’s signal The Hacker News recently reported Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access. Published context: July 21, 2026. Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass f ...

July 22, 2026 · 3 min · David Gomez

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Today’s signal The Hacker News recently reported Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution. Published context: July 21, 2026. Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary ...

July 21, 2026 · 3 min · David Gomez

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Today’s signal The Hacker News recently reported SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access. Published context: July 19, 2026. A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident res ...

July 20, 2026 · 3 min · David Gomez

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Today’s signal The Hacker News recently reported SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines. Published context: July 20, 2026. Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo ...

July 20, 2026 · 3 min · David Gomez

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Today’s signal The Hacker News recently reported GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft. Published context: July 17, 2026. Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gamb ...

July 18, 2026 · 3 min · David Gomez

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Today’s signal The Hacker News recently reported CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV. Published context: July 17, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS scor ...

July 17, 2026 · 3 min · David Gomez

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Today’s signal The Hacker News recently reported Zoom Patches Critical Windows Flaw That Could Enable Account Takeover. Published context: July 16, 2026. Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. “Improper Input Validation in Zoom Desktop Client f ...

July 16, 2026 · 3 min · David Gomez

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Today’s signal The Hacker News recently reported Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack. Published context: July 14, 2026. Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for b ...

July 15, 2026 · 3 min · David Gomez

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

Today’s signal The Hacker News recently reported iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days. Published context: July 13, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026- ...

July 13, 2026 · 3 min · David Gomez