2026-07-23
Cloudflare
Introducing Cache Response Rules
Talos Intelligence
Don’t swing at everything
MIT Technology Review
Supercooled kidneys have been transplanted into pigs in a “landmark achievement”
Amazon Security
Enterprise security at machine speed: AWS Black Hat 2026 preview
Github Security Blog
The case for a cooldown: Why Dependabot now waits before issuing version updates
Microsoft Security
Email threat landscape: Q2 2026 trends and insights
MIT Technology Review
The Download: energy transmission and US threats against Chinese AI
CISA Alerts & Advisories
Johnson Controls C-CURE 9000 and Victor application server
CISA Alerts & Advisories
Weintek cMT3092X
CISA Alerts & Advisories
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
CISA Alerts & Advisories
Johnson Controls XAAP Android
CISA Alerts & Advisories
MZ Automation libIEC61850
CISA Alerts & Advisories
MZ Automation lib60870
MIT Technology Review
How AI helps scientists design the next generation of medicines
CISA Alerts & Advisories
Panduit IntraVUE
Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
Schneier on Security
End-to-End Encryption and “Going Dark”
Offensive Security
The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?
Talos Intelligence
Preview: Cisco Talos at Black Hat USA 2026
Google Safety & Security
Introducing selfie for sign-in: a new, easy way to access your Google Account
MIT Technology Review
The power line that could reshape New York’s grid is hitting snags
Hunt and Hackett
Attackers do not need to break in, they simply log in
TrustedSec
CCPA Update: Who’s In Scope (Part 1)
Step Security
Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization
Elastic Security Labs
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
Elastic Security Labs
How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts
2026-07-22
Zero Salarium
PE OopsSec: Mind your PE, guard your OPSEC
Mend
199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ran
Dark Reading
Attackers Are Learning to Live Off the AI Toolchain
Ars Technica Security
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
Github Security Blog
Next chapter: Restructuring GitHub’s bug bounty program
Artem Golubin
Domain registration information should be transparent
Aikido
SQL injection isn't dead
NVISO Labs
Intercepting Android WebView traffic under new certificate validity requirement by Chromium
Black Hills Info Sec
The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success
Searchlight Cyber
Preemptive Threat Exposure Management: Frequently Asked Questions
Eclypsium
Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure
Searchlight Cyber
July 21st – This Week’s Top Cybersecurity and Dark Web Stories
MIT Technology Review
The Download: NASA’s new space telescope and OpenAI’s autonomous hacker
CISA Alerts & Advisories
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Schneier on Security
First-Person Identity Theft Story
MIT Technology Review
Shape-shifting mirrors on NASA’s new space telescope could unveil Jupiters like our own
Krebs on Security
LG to Ban Residential Proxies from Smart TV Apps
2026-07-21
Aikido
Tyro's CISO: Being the "Einstein of cybersecurity" isn't enough if developers don't trust you
Black Lantern Security
CVE-2026-12118 - IBM webMethods Integration Server: Pre-Auth RCE via WmServiceMock
Zero Day Initiative
Pwn2Own Ireland 2026 – New Targets and Categories
Héber Júlio
OSCP — The Good, Very Good, and the Bad
Amazon Security
Do more with AWS WAF labels using dynamic label interpolation
Bishop Fox Security
A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
Ars Technica Security
Apps targeted at US troops contain Chinese and Russian code
MIT Technology Review
The Download: Chinese AI divides the White House, and a record copyright payout
CISA Alerts & Advisories
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
CISA Alerts & Advisories
Rockwell Automation ThinManager
CISA Alerts & Advisories
Rockwell Automation 1718-AENTR/1719-AENTR
CISA Alerts & Advisories
Siemens Opcenter X
CISA Alerts & Advisories
Siemens SIDIS Secured SmartPlug
CISA Alerts & Advisories
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Alerts & Advisories
Tycon Systems TPDIN-Monitor-WEB2
CISA Alerts & Advisories
Siemens CADRA
CISA Alerts & Advisories
Rockwell Automation Studio 5000 Logix Designer
CISA Alerts & Advisories
Siemens IAM Client
CISA Alerts & Advisories
Rockwell Automation 1734 POINT I/O
CISA Alerts & Advisories
Rockwell Automation FactoryTalk Services Platform
Schneier on Security
MIT to Become Hotbed of AI Video Surveillance
Escape DAST
wp2shell (CVE-2026-63030 + CVE-2026-60137): WordPress pre-auth RCE, now detected by Escape
MIT Technology Review
Advancing next-gen AI with materials science innovation
Sicuranext Blog
Patching WP2Shell in the dark using PAI
Sicuranext Blog
Patching WP2Shell in the dark using PAI
Compass Security Blog
The Hidden Privilege of Automation Platforms
ISC SANS
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
Teleport Blog
Identity Security for AI
2026-07-20
Filippo Valsorda
Opaque, Interoperable Passkey Records (and a Go API)
Amazon Security
Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
Dark Reading
CISOs Feel the Heat Over AI Risk
Dark Reading
Attackers Combo Up Evasion Tactics for BEC Phishing
MIT Technology Review
China’s AI models have Trump’s AI world at war with itself
Exodus Blog
Dnsmasq DNS Remote Heap Buffer Overflow
Ars Technica Security
Pay up or not? Ransomware surge has victims facing tough choices.
Dark Reading
Cybersecurity Keeps Events 'Uneventful'
MIT Technology Review
The Download: AI hiring biases, and weather data sabotage
Escape DAST
Best AI DAST tools in 2026: ranked, compared, and reviewed for enterprise security teams
Schneier on Security
On Flock License Plate Tracking Cameras
Malwarebytes
A week in security (July 13 – July 19)
ISC SANS
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
Rosecurify
Seclog - #187
2026-07-19
Eye Security Research
wp2shell: incident response guide (CVE-2026-63030 + CVE-2026-60137)
Step Security
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
Bad Privacy
Should Canada’s Government Be More Transparent About the Slippery Slope of Enforcing Digital ID?
Project Black
Should I Domain Join Backup Servers?
2026-07-18
Elastic Security Labs
New North Korean campaign uses fake coding interviews to steal developer credentials
2026-07-17
Schneier on Security
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Dark Reading
Inc Ransomware Exploits SonicWall SMA Zero-Days
The Citizen Lab
US Military Smartphones Targeted Through Roaming and Ad Tech
Dark Reading
The Real AI Threat Is Blind Trust
Microsoft Security
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Bishop Fox Security
Using MCP Agents for Penetration Testing
Schneier on Security
Details of Alan Turing’s Voice Encryption System
Malwarebytes
How to use GitHub safely
ISC SANS
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
2026-07-16
Microsoft Security
ACR Stealer: Two observed intrusion chains amid increased threat activity
Dark Reading
Agentic AI: Taming the Unpredictable
Ars Technica Security
Now, even Russia's most elite hackers are using Clickfix to infect devices