Updated 04:40 PM IST

Cybersecurity News, Attacks & CVEs

Every attack, breach and CVE we cover gets its own plain-English ITVedas write-up β€” what happened, why it matters, and how to fix it. No links out, everything's on this page.

Last updated: 04:40 PM IST Β· July 21, 2026

Our own breakdowns of what happened

CVE-2026-505222026-07-21 Β· 04:40 PM IST

SharePoint Servers Under Fire as Remote Code Execution Flaw Gets Weaponized

AffectedMicrosoft SharePoint (specific versions not detailed in source)
SeverityCritical - allows remote code execution without authentication
FixApply security patches immediately; monitor for exploitation attempts
Full writeup β†’
πŸ”
Security2026-07-21 Β· 04:40 PM IST

AWS Coding Assistant Tricked Into Running Malicious Commands Hidden in Web Pages

Researchers reveal how AI-powered developer tools can be exploited through hidden text tricks to execute unauthorized code on developer machines.

Read full story β†’
πŸ”
Security2026-07-21 Β· 02:20 PM IST

New Awards Program Shines Spotlight on Industrial Cybersecurity Leaders

SecurityWeek introduces recognition program for OT security innovators, with winners announced at 2026 Nashville conference.

Read full story β†’
πŸ”
Security2026-07-21 Β· 02:20 PM IST

Cloud Infrastructure Flaw Could Allow Renters to Weaponize Power Consumption Against Energy Systems

Researchers discover method for cloud users to trigger cascading power grid failures through coordinated computing attacks.

Read full story β†’
πŸ”
Security2026-07-21 Β· 02:20 PM IST

Email Software Maker Fixes Multiple Security Holes Before Attackers Can Weaponize Them

Zimbra releases patches for dangerous vulnerabilities that could let hackers take control of email systems and steal data.

Read full story β†’
πŸ”
Security2026-07-21 Β· 02:20 PM IST

Criminal Gang Exploits Palo Alto Networks Flaw to Break Into Company Systems

Qilin ransomware operators using PAN-OS vulnerability to gain unauthorized access to networks before deploying encryption attacks.

Read full story β†’
πŸ”
Security2026-07-21 Β· 11:59 AM IST

Meta Rewards Security Expert $78,000 After Support System Flaw Exposed User Information

Meta paid a significant bug bounty after a researcher found improper access controls in its customer support platform.

Read full story β†’
πŸ”
Security2026-07-21 Β· 11:59 AM IST

Luxury Giant EstΓ©e Lauder Hit by Major Database Breach Through Enterprise Software Vulnerability

EstΓ©e Lauder confirms attackers stole sensitive customer data after exploiting a security flaw in business management software.

Read full story β†’
πŸ”
Security2026-07-21 Β· 11:59 AM IST

Hackers Found Using Microsoft 365 Calendar as Secret Messaging System

Attackers leverage hijacked Office 365 accounts to hide malware commands in calendar events, evading detection.

Read full story β†’
πŸ”
Security2026-07-21 Β· 11:59 AM IST

Major VPN Vulnerability Becomes Active Weapon in Ransomware Attacks

Cybercriminals exploiting critical Palo Alto security flaw to launch ransomware campaigns against businesses worldwide.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

Zimbra Releases Emergency Security Fixes for Multiple Critical Flaws

Popular email platform Zimbra patched severe security holes that could let attackers take control of systems and steal data.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

Hackers Already Targeting ServiceNow Software Flaw Just Days After Details Released

Attackers are exploiting a newly discovered ServiceNow flaw that allows them to run malicious code remotely on company systems.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

Clover Health Hit by Cyberattack Through Manipulated Employee Access

Healthcare insurance firm Clover Health confirms attackers gained access to sensitive patient and employee data via social engineering tactics.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

Hackers Deploy New Ransomware Targeting AI Systems Through ServiceNow Vulnerability

Attackers exploiting ServiceNow flaw to install AI-focused ransomware that destroys machine learning models and data.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

Critical WordPress Flaws Create Perfect Storm for Website Takeovers

Two newly discovered WordPress vulnerabilities working together allow hackers complete control of websites without needing login credentials.

Read full story β†’
πŸ”
Security2026-07-21 Β· 09:39 AM IST

WordPress Plugin Flaw Triggers Wave of Automated Attacks as Hackers Share Easy-to-Use Tools

A serious vulnerability in a WordPress plugin is spreading rapidly as criminals use publicly available hacking tools to target websites.

Read full story β†’
πŸ”
Security2026-07-20 Β· 11:14 PM IST

Cryptocurrency Platform Loses Millions After Attackers Exploit Corporate Network Flaws

Hackers breached a crypto firm through unpatched security gaps in widely-used VPN equipment, stealing $23.7M in digital assets.

Read full story β†’
πŸ”
Security2026-07-20 Β· 11:14 PM IST

Major Beauty Brand Hit by Software Vulnerability Attack; Hackers Steal Customer Data

EstΓ©e Lauder discloses breach tied to unpatched software flaw affecting personnel systems and customer information.

Read full story β†’
πŸ”
Security2026-07-20 Β· 11:14 PM IST

Luxury Beauty Giant EstΓ©e Lauder Hit by Security Vulnerability in Business Software

EstΓ©e Lauder confirms customer data was compromised through a weakness in Oracle's enterprise accounting system.

Read full story β†’
πŸ”
Security2026-07-20 Β· 10:12 PM IST

AI Coding Tools Exploited to Steal Model Data and Deploy Ransomware

Security researchers reveal how attackers manipulated AI assistants to bypass safety measures and encrypt critical machine learning systems.

Read full story β†’
πŸ”
Security2026-07-20 Β· 08:40 PM IST

Massive GitHub Poisoning Attack: Over 7,600 Repositories Weaponized to Deliver Malware

Attackers compromised thousands of code repositories to distribute dangerous malware to unsuspecting developers.

Read full story β†’