Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

Pierluigi Paganini July 19, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

OpenSSL Fixes HollowByte Memory Exhaustion Bug
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
A cyberattack hit Nichirei, one of Japan’s largest food companies
New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack
TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog
SonicWall warns of active exploitation of two SMA 1000 zero-days
Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
Attacker Used AI to Build Custom PowerShell Recon Malware
Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
Dutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.

International Press – Newsletter

Cybercrime

Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy  

Investigation into Odido hack points to possible involvement of the Dutch  

German firm files for insolvency, blames cybercrims who shut down production for 6 weeks

Japan’s largest taxi operator shuts systems after cyberattack

Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 

Two sentenced for hacking Transport for London in UK’s biggest ever cyber crime case  

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Malware

CrashStealer: C++ macOS infostealer posing as crash reporter

Lucide Proxy: Turning Student Web Proxies into DDoS Bots      

AsyncAPI npm organization compromised, 2M weekly downloads affected  

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains  

NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era  

Hacking

Large-scale exploitation campaign targeting website content management systems (CMS)  

Analyzing AI-Augmented Network Enumeration  

LegacyHive public disclosure 

Claude for-Chrome Extension-Bypass

Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8n  

wp2shell: Pre Authentication RCE in WordPress Core  

OpenSSL HollowByte: A DoS Hiding in 11 Bytes  

wp2shell: Pre Authentication RCE in WordPress Core  

Intelligence and Information Warfare  

EU targets Russian intelligence officers accused of running a yearslong cyberspying campaign  

NSA revives ‘Tailored Access Operations’ name for elite hacking unit  

UK and EU strike Russian cyber networks with new sanctions  

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says  

Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries  

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

New North Korean campaign uses fake coding interviews to steal developer credentials

Cybersecurity

xAI Grok CLI Uploads Full Repos and Secrets, Opt-Out Ignored  

Satya Nadella’s ‘Reverse Information Paradox’ post draws reactions from AI leaders

BabeLLM: A unified taxonomy for NLP-based LLM cybersecurity applications  

Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans 

The July 2026 Security Update Review  

A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers 

AI Data Centers Are Being Built Faster Than They Can Be Secured

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei  

Ernst & Young discloses data breach after support system hack  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment