Microsoft Patches 570 Flaws & ServiceNow RCE – Weekly News Roundup

Here is the most recent Cybersecurity news for the past week: πŸ› οΈMicrosoft July 2026 Patch Tuesday Addresses Massive 570 Flaws, 3 Zero-Days
Microsoft released a record-breaking Patch Tuesday addressing 570 vulnerabilities, including three zero-days and two actively exploited flaws affecting Active Directory Federation Services and SharePoint Server. The release reinforces the growing challenge organizations face in prioritizing and deploying security updates at scale.
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/

⚑ServiceNow AI Platform RCE Vulnerability Under Active Exploitation
Researchers observed active exploitation of a critical remote code execution vulnerability affecting the ServiceNow AI platform shortly after disclosure. The flaw allows unauthenticated attackers to escape the application sandbox and execute arbitrary code on self-hosted deployments.
https://www.securityweek.com/exploitation-of-servicenow-vulnerability-seen-days-after-disclosure/

πŸ€–Google Launches Gemini 3.5 Flash Cyber for Vulnerability Discovery
Google DeepMind introduced Gemini 3.5 Flash Cyber, an AI model purpose-built to discover, validate, and help remediate software vulnerabilities. The model demonstrated impressive results across major open-source projects and enterprise codebases, highlighting AI’s growing role in defensive security.
https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html

🚨SonicWall Issues Emergency Patches for SMA1000 Zero-Days Under Active Attack
SonicWall released urgent security updates after attackers began chaining two zero-day vulnerabilities to achieve unauthenticated remote code execution against SMA1000 secure remote access appliances. Customers are strongly encouraged to patch immediately.
https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/

🌐WP2Shell Flaws Exploited in Wild Against WordPress Websites
Attackers have begun exploiting two critical vulnerabilities affecting WordPress shortly after public disclosure. By chaining SQL injection and remote code execution flaws, attackers can gain complete control of vulnerable websites running recent WordPress releases.
https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/

https://gbhackers.com/sap-patch-day-fixes-critical-flaws/

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.