1. SharePoint zero-day under active attack forces federal patch deadline. CISA added CVE-2026-58644, a critical (CVSS 9.8) deserialization flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, giving Federal Civilian Executive Branch agencies until July 19 to remediate. The bug allows unauthenticated remote code execution and was weaponized as […]
Hackers: Who Is Actually Trying to Break Into Your Systems?
Picture the hackers. If a teenage boy in a dark bedroom came to mind, hood up, soda cans on the floor, you are not alone. That image has been marketed to us for thirty years.It is also mostly wrong, and believing it can cost a small business or a county office real money. I have […]
Cybersecurity Weekly Roundup: Week of July 6 – July 12, 2026
Top 5 Cyber Security News Stories 1. ShinyHunters Exploit Oracle PeopleSoft Flaw, Hit 100+ Organizations Including Nissan The ShinyHunters group ran a sweeping campaign this week exploiting a vulnerability in Oracle PeopleSoft to break into HR and payroll systems at more than 100 organizations. Nissan was among the most prominent victims, with attackers exfiltrating sensitive […]
10 Cyber Security Wake-Up Calls The First Half of 2026
In April, Chelan County, Washington, shut down its entire network, phone lines, and public websites after a malware attack, and officials had no timeline for when normal service would return. That is not a hypothetical scenario from a conference slide. That is six months into 2026, and it is one of 10 stories that tell […]
Cyber Security Weekly Roundup: Week of June 29 – July 5, 2026
1. FBI Dismantles NetNut, One of the World’s Largest Residential Proxy Networks On July 3, the FBI and private-sector partners took down NetNut, a residential proxy service built on roughly 2 million secretly hijacked home devices. The network had quietly routed criminal traffic — from credential stuffing to fraud — through ordinary people’s routers and […]
Cyber Security Weekly: Top 5 News Stories for the Week of June 22–28, 2026
1. LastPass Confirms Customer Data Stolen in Klue Supply Chain Breach LastPass disclosed that the Icarus extortion group used OAuth tokens stolen in a supply chain attack against market-intelligence vendor Klue to access customer records within its Salesforce environment. Exposed data included names, phone numbers, email and physical addresses, and support case records, though LastPass […]






