The European Union is preparing for the Cyber Resilience Act (CRA) with ENISA expanding its role in the CVE Program, onboarding new CNAs like NCIA and AISLE to manage vulnerability reporting ahead of the September 2026 mandate for manufacturers. Meanwhile, the Qilin ransomware group continues its double-extortion tactics, adding Chun Tai Sing Chemical Industry to its leak site.
Critical vulnerabilities remain actively exploited. Microsoft Threat Intelligence reports Storm-1175 is leveraging a flaw in N-able N-central (CVE-2026-18577) to deploy a new custom ransomware, StormEncryptor, targeting MSPs. A Metabase zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf) is also being exploited for admin access, with updated patch versions released and new detection methods identified.
In supply chain attacks, PhantomCore RAT has been identified as the backdoor used in a Head Mare campaign targeting Russian organizations via compromised TrueConf installers. WordPress has patched a high-severity 'XSS2Shell' flaw (CVE-2026-64638) that could lead to remote code execution.
On the incident response front, Suisun City, California, declared a state of emergency after a cyberattack disrupted 911 services. IEH Corporation disclosed that a phishing attack compromised an employee's Microsoft 365 account, exposing sensitive defense-related data.
Proactive measures are also being taken. California has launched an AI Cyber Defense Program to protect critical infrastructure, and the Netherlands has finalized its NIS2 law, effective August 15, 2026, imposing new obligations on thousands of organizations.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.