July 2026 (30)
ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)
3 CVEsServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.
Potential Ransomware Note File Dropped via SMB
1 rule 4 TTPsElastic has released a detection rule to identify the creation of ransomware note files by the Windows System process (PID 4) via the SMB protocol, indicating a remote ransomware attack often leveraging lateral movement to perform data encryption, destruction, or inhibit system recovery.
Suspicious File Renaming via SMB Indicating Remote Ransomware Activity
1 rule 4 TTPsThis threat brief details a high-severity detection rule that identifies remote ransomware activity on Windows systems, leveraging SMB to initiate rapid, high-entropy file renames by the System process (PID 4) on user-owned files, which often signifies data encryption for impact.
Perl Denial of Service Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Perl to cause a Denial of Service condition.
Octopus Deploy: Vulnerability Allows Security Bypass
1 TTPA remote, authenticated attacker can exploit a vulnerability in Octopus Deploy to bypass security measures, potentially leading to unauthorized access or actions within the affected system.
Multiple WebKitGTK Vulnerabilities
4 TTPsMultiple vulnerabilities exist in WebKitGTK that can be exploited by a remote, unauthenticated attacker for information disclosure, denial of service, data manipulation, and security mechanism bypass.
Bitdefender Internet and Total Security Vulnerability Allows Privilege Escalation
1 TTPA local attacker can exploit a vulnerability in Bitdefender Internet Security and Bitdefender Total Security to elevate their privileges on the affected system.
Multiple Vulnerabilities in Zoom Video Communications Rooms and Workplace
2 TTPsMultiple vulnerabilities have been identified in Zoom Video Communications Rooms and Zoom Video Communications Workplace, which an attacker can exploit to elevate privileges and ultimately take control of a user account.
Devolutions Server: Multiple Vulnerabilities Allow Authenticated Attackers to Manipulate Data, Bypass Security, and Disclose Information
4 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.
Netty: Multiple Vulnerabilities
1 TTPAn attacker can exploit multiple vulnerabilities within the Netty framework to bypass security checks, manipulate requests or headers, circumvent certificate validations, and cause a denial of service.
AWS Bedrock Model Prompt or Completion Containing Credentials
1 rule 1 TTPA detection rule identifies AWS access key IDs, Amazon Bedrock API keys, PEM private-key blocks, and GitHub/GitLab tokens within Amazon Bedrock model prompts or completions, indicating a critical credential exposure event through misconfiguration, data leakage, or prompt injection that necessitates immediate secret rotation and investigation.
Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service
1 TTPA vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.
SonicWall SMA: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.
Sophos State of Ransomware 2026 Report Highlights Evolving Attack Vectors
8 TTPsThe Sophos State of Ransomware 2026 report indicates that while median ransom payments are dropping, successful data encryption by ransomware attackers is climbing, with malicious email, phishing, and compromised credentials now surpassing exploited vulnerabilities as the primary initial access vectors, often leveraging identity-based attacks against critical systems like VPNs and firewalls.
Citrix Secure Access Client for Windows Vulnerabilities Lead to Privilege Escalation and Information Disclosure
2 TTPsMultiple vulnerabilities in Citrix Systems Secure Access Client for Windows can be exploited by a local attacker to achieve privilege escalation and information disclosure on affected Windows systems.
Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution
1 TTPMultiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.
Multiple Vulnerabilities in Fortinet FortiSIEM
3 TTPsMultiple vulnerabilities have been identified in Fortinet FortiSIEM that could allow an attacker to perform Cross-Site Scripting (XSS) attacks or achieve arbitrary code execution, enabling unauthorized script injection into web pages or direct execution of attacker-controlled code within the system.
MetaGuru HCM SQL Injection Vulnerability (CVE-2026-15804)
2 TTPs 1 CVEA SQL Injection vulnerability (CVE-2026-15804) in MetaGuru's HCM software allows authenticated remote attackers to inject SQL commands via specific parameters, compromising database confidentiality, integrity, and availability.
OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision
1 TTP 1 CVEA high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.
RabbitMQ Management UI UNC SSRF Vulnerability (CVE-2026-57211) on Windows
1 CVECVE-2026-57211 details a Server-Side Request Forgery (SSRF) vulnerability within the RabbitMQ management UI when deployed on Windows, enabling an attacker to coerce the server into making requests to arbitrary UNC paths, potentially leading to NTLM credential disclosure or internal network reconnaissance.
RabbitMQ Topic Authorization Bypass via Cross-Tenant Routing-Key Vulnerability
1 CVECVE-2026-57217 details a vulnerability in RabbitMQ where topic authorization can be bypassed, leading to cross-tenant routing-key bypass, potentially allowing unauthorized access to or manipulation of routing keys in a multi-tenant environment.
RabbitMQ Stream Listener Vulnerability CVE-2026-57220 Allows Unauthenticated Memory Exhaustion DoS
1 TTP 1 CVEA denial-of-service vulnerability, CVE-2026-57220, exists in the RabbitMQ stream listener that allows an unauthenticated attacker to exhaust memory resources by not properly enforcing frame-size limits during authentication, leading to service disruption.
GitHub CLI `gh codespace jupyter` Command Remote Code Execution Vulnerability
1 TTP 1 CVEA remote code execution vulnerability, CVE-2026-59831, has been identified in the GitHub CLI's `gh codespace jupyter` command, allowing attackers to execute arbitrary code on a user's system when connecting to a specially crafted malicious Codespace.
Perl Regex Engine Vulnerability Allows Silently Incorrect Matches
1 CVEA vulnerability exists in Perl versions up to and including 5.43.9 where regular expression matches can be silently incorrect when an alternation of more than 65535 fixed string branches is compiled into a trie within the Perl_study_chunk function, potentially leading to incorrect logic or data processing.
RabbitMQ Unauthenticated OAuth Client Credential Disclosure via HTTP API (CVE-2026-57219)
1 TTP 1 CVECVE-2026-57219 describes an unauthenticated disclosure vulnerability in RabbitMQ, allowing an attacker to obtain OAuth client credentials via an HTTP API endpoint when RabbitMQ is configured with certain less common OAuth 2 configurations, potentially leading to unauthorized access to other systems or services.
Libarchive Heap Overflow and Out-of-Bounds Read via Pax Extended Header (CVE-2026-15028)
1 CVEA heap overflow and out-of-bounds read vulnerability (CVE-2026-15028) has been identified in the Libarchive library, triggered by parsing a tar archive with a specially crafted pax extended header, potentially leading to denial of service or arbitrary code execution.
CVE-2025-44904 HDF5 Heap Buffer Overflow in H5VM_memcpyvv Function
1 CVECVE-2025-44904 describes a heap buffer overflow vulnerability in HDF5 version 1.14.6 that occurs via the H5VM_memcpyvv function, which could lead to potential security risks such as denial of service or arbitrary code execution.
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
2 rules 7 TTPs 26 IOCsThreat actors are actively exploiting Microsoft's ClickOnce deployment technology, leveraging its low user interaction, lack of privilege requirements, and built-in update mechanisms to deliver malware, establish persistence, and maintain remote access, often executing payloads within legitimate rundll32.exe and dfsvc.exe processes.
Multiple Vulnerabilities in Python Lead to Denial of Service
1 TTPRemote and unauthenticated attackers can exploit multiple unspecified vulnerabilities within Python to conduct Denial of Service attacks, potentially disrupting the availability of services or applications running on the language.
Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.