This week the threat landscape sharpened around two themes: the weaponization of AI agents and the exploitation of trusted access. A single link could forge a rogue AI insider, extortion crews leaned on the phone rather than the exploit, and a fired employee’s credentials became a live breach. Here is what mattered, and what to […]
Cyber Security Weekly Roundup: The Week of July 13-19, 2026
1. SharePoint zero-day under active attack forces federal patch deadline. CISA added CVE-2026-58644, a critical (CVSS 9.8) deserialization flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, giving Federal Civilian Executive Branch agencies until July 19 to remediate. The bug allows unauthenticated remote code execution and was weaponized as […]
Cybersecurity Weekly Roundup: Week of July 6 – July 12, 2026
Top 5 Cyber Security News Stories 1. ShinyHunters Exploit Oracle PeopleSoft Flaw, Hit 100+ Organizations Including Nissan The ShinyHunters group ran a sweeping campaign this week exploiting a vulnerability in Oracle PeopleSoft to break into HR and payroll systems at more than 100 organizations. Nissan was among the most prominent victims, with attackers exfiltrating sensitive […]
Cyber Security Weekly Roundup: Week of June 29 – July 5, 2026
1. FBI Dismantles NetNut, One of the World’s Largest Residential Proxy Networks On July 3, the FBI and private-sector partners took down NetNut, a residential proxy service built on roughly 2 million secretly hijacked home devices. The network had quietly routed criminal traffic — from credential stuffing to fraud — through ordinary people’s routers and […]
Cyber Security Weekly: Top 5 News Stories for the Week of June 22–28, 2026
1. LastPass Confirms Customer Data Stolen in Klue Supply Chain Breach LastPass disclosed that the Icarus extortion group used OAuth tokens stolen in a supply chain attack against market-intelligence vendor Klue to access customer records within its Salesforce environment. Exposed data included names, phone numbers, email and physical addresses, and support case records, though LastPass […]
Cyber Security Weekly: Top 5 News Stories for the Week of June 15th
1. Cisco Catalyst SD-WAN Manager zero-day under active exploitation (CVE-2026-20245). Attackers are actively exploiting a privilege-escalation flaw in Cisco Catalyst SD-WAN Manager that lets an authenticated local user upload a crafted file and execute commands as root. At the time of writing, no patch is available, leaving network operators dependent on access controls and monitoring. […]






