📰 DAILY THREAT BRIEFING
Tuesday, July 21, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 21, 2026.

  1. Estée Lauder discloses data breach via Oracle E-Business flaw
    — Bleeping Computer

    Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the co…
  2. SonicWall SMA1000 flaws exploited as zero-days to push custom malware
    — Bleeping Computer

    Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install cus…
  3. Hackers steal $23.7 million in crypto from Ostium in off-chain attack
    — Bleeping Computer

    The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising …
  4. 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
    — Dark Reading

    Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against…
  5. Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
    — Bleeping Computer

    Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools la…
  6. Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
    — Dark Reading

    Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability …
  7. CISOs Feel the Heat Over AI Risk
    — Dark Reading

    Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their po…
  8. WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
    — SANS ISC

    Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced w…
  9. Attackers Combo Up Evasion Tactics for BEC Phishing
    — Dark Reading

    "The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Rem…
  10. FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
    — The Hacker News

    Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intellig…
  11. Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
    — The Hacker News

    A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filena…
  12. HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
    — The Hacker News

    A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions…

Generated by HiveNet.ai Threat Intelligence Platform · July 21, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC