Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Tenable is hosting SWARM, a build event at Black Hat 2026, for security practitioners to collaboratively create and improve agentic, open-source tooling. The goal is to drive collective defense and stop adversaries together.
FortiGuard Labs has uncovered a global phishing campaign using obfuscated JScript and disguised .ttf (TrueType Font) files to deliver malware. The attackers employ Lua loaders with low detection rates to distribute remote access trojans (RATs) and infostealers, including Agent Tesla and Remcos.
Microsoft disclosed two actively exploited zero-day vulnerabilities, CVE-2026-56164 and CVE-2026-56155, as part of its July 2026 Patch Tuesday updates. CVE-2026-56164 is a critical remote privilege escalation flaw in on-premises SharePoint Server, requiring no credentials or user interaction, making it highly exploitable for internet-facing systems.
CVE-2026-56164 and CVE-2026-56155 are actively exploited Microsoft zero-days affecting SharePoint and AD FS.
This article discusses two zero-day vulnerabilities exploited in the wild, affecting Microsoft SharePoint Server and Active Directory Federation Services. The SharePoint bug is remotely exploitable with no authentication required, while the AD FS flaw enables privilege escalation from a low-privileged position.
This article discusses two zero-day vulnerabilities exploited in the wild, affecting Microsoft SharePoint Server and Active Directory Federation Services. The SharePoint bug is remotely exploitable with no authentication required, while the AD FS flaw enables privilege escalation from a low-privileged position.