entdigest

7 articles from 36 sources · Updated 2026-07-20 23:00 UTC

Top Stories

  1. Estée Lauder discloses data breach via Oracle E-Business flawBleepingComputer
  2. SonicWall SMA1000 flaws exploited as zero-days to push custom malwareBleepingComputer
  3. Hackers steal $23.7 million in crypto from Ostium in off-chain attackBleepingComputer
  4. 'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverDark Reading
  5. Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapesBleepingComputer
  6. JadePuffer agentic attacks now target AI model data with ransomwareBleepingComputer
  7. Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation PushDark Reading

Latest

E

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

The big picture: Estée Lauder discloses data breach via Oracle E-Business... — should prompt a review of your own security.

BleepingComputer Security 1 min read Read →
S

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]

BleepingComputer reports: SonicWall SMA1000 flaws exploited as zero-days to push... — this underscores the cost of weak defenses.

BleepingComputer Security 1 min read Read →
H

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]

Why it matters: Hackers steal $23.7 million in crypto from Ostium... is a wake-up call for digital security.

BleepingComputer Security 1 min read Read →
'

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

Why it matters: 'WP2Shell' Opens Millions of WordPress Sites to Remote... underscores the cost of weak defenses.

Dark Reading Security 1 min read Read →
C

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]

Bottom line from BleepingComputer: this exposes vulnerabilities that affect millions.

BleepingComputer Security 1 min read Read →
J

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]

Bottom line from BleepingComputer: this underscores the cost of weak defenses.

BleepingComputer Security 1 min read Read →
R

Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push

Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.

Dark Reading reports: Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push — this should prompt a review of your own security.

Dark Reading Security 1 min read Read →