ServiceNow AI Platform Just Got Pre-Auth RCE’d, Wild Exploits Started Friday
ServiceNow AI Platform pre-auth RCE (CVE-2026-6875, CVSS 9.5) hit 85% of Fortune 500. Wild exploits started July 18. ServiceNow still won’t confirm it.
ServiceNow AI Platform pre-auth RCE (CVE-2026-6875, CVSS 9.5) hit 85% of Fortune 500. Wild exploits started July 18. ServiceNow still won’t confirm it.
SharePoint zero-day CVE-2026-58644 (CVSS 9.8) was exploited before Microsoft’s July 14 patch shipped. CISA deadline hits July 19. What admins need to do.
JadePuffer AI Ransomware ran a full attack with no human at keyboard. Sysdig details Langflow CVE-2025-3248, 31s self-correction, 1,342 configs hit.
Nissan employee SSNs, banking data, tax records exposed via Oracle PeopleSoft zero-day CVE-2026-35273. ShinyHunters hit 300+ servers across 100 orgs May 27-Jun 9, 2026.
ShareFile vulnerability: Progress ordered customers to shut down Storage Zone Controllers over a credible threat, with no patch and no CVE.
Accenture data breach: ‘888’ claims 35GB of source code, RSA keys, and Azure tokens stolen. Accenture confirms an isolated incident on July 8, 2026.
AirDrop vulnerability: CISPA researchers found 6 flaws in AirDrop and Quick Share affecting 5 billion iPhones and Androids. Zero-click crashes, sharingd takedowns, and what to change now.
Mercor 4TB breach: $10B AI startup Mercor hid a LiteLLM supply chain hack for 3 months. Passport scans, SSNs, biometrics, and Meta contract fallout, all in one timeline.
Gaslight malware doesn’t just hide from antivirus software, it tries to convince AI analysis tools the investigation itself is broken. Here’s how it works.
LastPass data breach via the Klue hack exposed CRM data, not vaults. Here’s exactly what happened, who’s affected, and what to do next.