Cybersecurity News

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

Wed, 15 Jul 2026 17:20:01 +0530
The Hacker News

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Wed, 15 Jul 2026 16:37:07 +0530
The Hacker News

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

Wed, 15 Jul 2026 16:36:57 +0530
The Hacker News

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Wed, 15 Jul 2026 16:25:22 +0530
The Hacker News

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Wed, 15 Jul 2026 14:46:13 +0530
The Hacker News

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Wed, 15 Jul 2026 11:00:21 +0530
The Hacker News

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Wed, 15 Jul 2026 01:55:47 +0530
The Hacker News

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

Tue, 14 Jul 2026 23:47:57 +0530
The Hacker News

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could