Application securityHugging Face uses GLM 5.2 to investigate AI agent-driven cyberattackLaura FrenchJuly 20, 2026Hugging Face turned to an open-weight model after being restricted by frontier model guardrails.
Cloud SecurityCritical ServiceNow AI flaw exploited days after patch releaseSteve ZurierJuly 20, 2026Attackers exploit critical ServiceNow AI bug just days after security patch release.
Application securityOver 1 million malicious emails found using text salting to fool AI scannersLaura FrenchJuly 17, 2026Text salting fills emails with hidden benign content to mask malicious phishing lures.
RansomwareStolen identities cause 79% of ransomware attacks, says Sophos reportSteve ZurierJuly 17, 2026Identity failures replace software flaws as ransomware's top access vector.
Vulnerability ManagementCritical Oracle EBS bug added to CISA list of exploited vulnerabilitiesLaura FrenchJuly 17, 2026The flaw allows an unauthenticated attacker to remotely compromise Oracle Payments.
RansomwareAttackers execute a complete ransomware operation in under 24 hoursSteve ZurierJuly 16, 2026Spirals ransomware encrypted a victim in under 24 hours, underscoring the need for rapid containment.
AI/MLCISOs Build Practical Playbook for Governing Agentic AIKelley DamoreJuly 16, 2026A practitioner-built framework for securing, and scaling agentic AI
Vulnerability ManagementCISA warns that three SharePoint Server bugs are actively exploitedSteve ZurierJuly 15, 2026Federal agencies given to July 17 to make the patches.
MalwareMacOS ‘CrashStealer’ malware poses as crash reporter to steal credentialsLaura FrenchJuly 15, 2026The malware is written in C++ and uses a signed and notarized dropper to evade Gatekeeper.
IdentityOAuth client ID spoofing silently validates stolen Microsoft Entra ID credentialsSteve ZurierJuly 14, 2026Attackers run multiple spoofing campaigns to confirm credentials.