RedHawk Threat Watch • Live public education feed

Current hacks, new threats, exploited vulnerabilities, and 0-day alerts.

This page helps customers understand what is happening in the cyber world without copying other people’s work. RedHawk shows short source-provided snippets, defensive context, and clear links back to the original publishers.

60current items
17exploited / 0-day tags
40CVE-related items
2ransomware tags
Updated: Jul 22, 2026 7:22 AM UTC Cache: fresh No SQL database Attribution-first

Today’s feed

Rule: learn from the source, do not steal the source. Every card links back to the original publisher. Summaries are intentionally short.

The Hacker News Jul 22, 2026 malware

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the p…

Read original source →
The Hacker News Jul 22, 2026 news

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a promp…

Read original source →
The Hacker News Jul 22, 2026 news

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models were operating with "reduced cyber refusals for evaluation purposes" that might …

Read original source →
KrebsOnSecurity Jul 22, 2026 news

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties …

Read original source →
The Hacker News Jul 21, 2026 news

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed to the company by Tyler Murphy, co-…

Read original source →
The Hacker News Jul 21, 2026 news

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has p…

Read original source →
The Hacker News Jul 21, 2026 news

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender a…

Read original source →
The Hacker News Jul 21, 2026 CVE

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over …

Read original source →
The Hacker News Jul 21, 2026 ransomwareCVE

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass …

Read original source →
The Hacker News Jul 21, 2026 news

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP noti…

Read original source →
The Hacker News Jul 21, 2026 news

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent framewor…

Read original source →
The Hacker News Jul 21, 2026 news

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock…

Read original source →
The Hacker News Jul 21, 2026 news

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence sp…

Read original source →
CISA Known Exploited Vulnerabilities Jul 21, 2026 Known exploitedCVE

CVE-2026-60137 — WordPress Core — WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress… Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-08-04

Read original source →
CISA Known Exploited Vulnerabilities Jul 21, 2026 Known exploitedCVE

CVE-2026-63030 — WordPress Core — WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-24

Read original source →
CISA Known Exploited Vulnerabilities Jul 21, 2026 Known exploitedCVE

CVE-2026-0770 — Langflow Langflow — Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-24

Read original source →
CISA Known Exploited Vulnerabilities Jul 21, 2026 Known exploitedCVE

CVE-2021-27137 — DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-24

Read original source →
CISA Known Exploited Vulnerabilities Jul 16, 2026 Known exploitedCVE

CVE-2026-58644 — Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-19

Read original source →
CISA Known Exploited Vulnerabilities Jul 16, 2026 Known exploitedCVE

CVE-2026-25089 — Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-19

Read original source →
CISA Known Exploited Vulnerabilities Jul 16, 2026 Known exploitedCVE

CVE-2026-39808 — Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-19

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-49501 — Newly published vulnerability

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-56287 — Newly published vulnerability

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a craf…

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-57821 — Newly published vulnerability

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a b…

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-35152 — Newly published vulnerability

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. T…

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-14251 — Newly published vulnerability

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

Read original source →
NVD Recent CVEs Jul 15, 2026 CVE

CVE-2026-15583 — Newly published vulnerability

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.

Read original source →
CISA Known Exploited Vulnerabilities Jul 15, 2026 Known exploitedCVE

CVE-2026-46817 — Oracle E-Business Suite — Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payme… Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-18

Read original source →
CISA Known Exploited Vulnerabilities Jul 15, 2026 Known exploitedCVE

CVE-2023-4346 — KNX Association KNX Protocol Connection Authorization Option 1 — KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the d… Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-29

Read original source →
KrebsOnSecurity Jul 14, 2026 news

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificia…

Read original source →
CISA Known Exploited Vulnerabilities Jul 14, 2026 Known exploitedCVE

CVE-2026-56155 — Microsoft Active Directory Federation Services — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-28

Read original source →
CISA Known Exploited Vulnerabilities Jul 14, 2026 Known exploitedCVE

CVE-2026-56164 — Microsoft SharePoint Server — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-17

Read original source →
CISA Known Exploited Vulnerabilities Jul 14, 2026 Known exploitedCVE

CVE-2026-15409 — SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-17

Read original source →
CISA Known Exploited Vulnerabilities Jul 14, 2026 Known exploitedCVE

CVE-2026-15410 — SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-17

Read original source →
KrebsOnSecurity Jul 13, 2026 identity threat

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response…

Read original source →
CISA Known Exploited Vulnerabilities Jul 13, 2026 Known exploitedCVE

CVE-2008-4128 — Cisco IOS — Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec… Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-16

Read original source →
CISA Known Exploited Vulnerabilities Jul 10, 2026 Known exploitedCVE

CVE-2026-56291 — Balbooa Forms — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-13

Read original source →
CISA Known Exploited Vulnerabilities Jul 10, 2026 Known exploitedCVE

CVE-2026-48939 — iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Not… Due: 2026-07-13

Read original source →
KrebsOnSecurity Jul 8, 2026 0Day / exploited

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Read original source →
KrebsOnSecurity Jul 2, 2026 malware

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security…

Read original source →
KrebsOnSecurity Jun 23, 2026 news

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first…

Read original source →
KrebsOnSecurity Jun 18, 2026 malware

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operate…

Read original source →
KrebsOnSecurity Jun 10, 2026 ransomware

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gen…

Read original source →
KrebsOnSecurity Jun 9, 2026 news

A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly…

Read original source →
KrebsOnSecurity Jun 1, 2026 news

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting account passwords.

Read original source →