This daily summary highlights critical updates and new threats impacting the cybersecurity landscape. JADEPUFFER, an AI-driven ransomware, has evolved to target and destroy AI/ML models, including PyTorch and TensorFlow, by re-exploiting CVE-2025-3248 in Langflow. This destructive campaign now involves container escapes and focuses on intellectual property loss.
SonicWall is warning of active exploitation of two zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) in its SMA 1000 devices. Inc Ransomware and the UTA0533 group are leveraging these flaws, with UTA0533 deploying custom malware for persistence and credential theft. Remediation now requires a full device reset if compromise is suspected.
Identity attacks have surpassed exploits as the leading ransomware vector, with compromised credentials (T1078) and exploited public-facing applications (T1190) being key. This shift emphasizes the importance of robust identity security and multi-factor authentication.
Ransomware attacks saw a 20% year-over-year increase in H1 2026, driven by competition between Qilin and The Gentlemen groups. U.S. SMBs remain a primary target.
A critical vulnerability chain, 'wp2shell', in WordPress Core (CVE-2026-63030 and CVE-2026-60137) allows unauthenticated RCE. Public exploits are available, and WordPress is initiating forced automatic updates.
New threats include the 'SleeperGem' supply chain attack on RubyGems, a data breach at healthcare software firm Craneware, and the 'payload' ransomware group targeting CKR Consulting Engineers. Oracle's July 2026 Critical Patch Update will include 1,455 fixes, many for remotely exploitable vulnerabilities.
Governments are considering bans on ransomware payments, with the U.K. planning a ban for public sector and critical infrastructure. ReliaQuest is partnering with OpenAI to advance AI in cyber defense.
Users are warned about free VPN browser extensions harvesting clipboard data. Finally, a report indicates enterprises are overwhelmed by disjointed security tools, creating expanded attack surfaces exacerbated by AI and non-human identities.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.