Claude Security scans now run on Claude Mythos 5, available today in public beta for all Claude Enterprise customers.
Put our most capable security model to work on your codebase, no separate model access needed.
Apple’s latest security update fixes multiple vulnerabilities related to how devices process images.
In some attacks, opening a malicious image could give attackers access to your device.
Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS).
An authenticated, low-privileged attacker with network access could manipulate certificate enrollment to impersonate a Domain Controller, potentially enabling privileged operations and full domain compromise. Exploitation requires no administrative privileges or user interaction, but does require network access and a valid domain account.
The publication of proof-of-concept code increases the likelihood of exploitation attempts, so we recommend customers prioritize installing the July 2026 security update as soon as possible. Microsoft has observed researcher testing activity but has not confirmed active exploitation by threat actors. In response to these early signs of activity, we are sharing detection and hunting guidance to help defenders identify potential exploitation attempts, particularly in environments where the security update has not yet been applied.
Microsoft Defender detects malicious certificate requests associated with this vulnerability and generates the alert:
- “Potential Certighost (CVE-2026-54121) AD CS abuse.”
- "Active Directory Certificate Services attack tool activity "
Other alerts, including the following, may also appear during the attack chain. These signals support investigation but are not independently specific to Certighost.
- Security principal reconnaissance (LDAP)
- Suspicious Active Directory Certificate Services abuse tool activity
- Suspected suspicious Kerberos ticket request
- DCSync attack (replication of directory services)
Customers should apply the July 14, 2026 security update to every server running an Enterprise Certification Authority (CA). The security update provides the primary protection by validating the enrollment chase target before the CA contacts it, preventing invalid or attacker-controlled systems from influencing certificate issuance.
Customers who can't apply the July 14, 2026 security update immediately for all affected servers, should consider configuring the following audit logs to enable the mentioned detections and forensic:
- Enable Certification Services auditing for both successful and failed operations.
- Configure the CA audit filter to capture certificate lifecycle activity.
- Monitor Security events 4886 and 4887 for anomalous certificate requests and issuance.
- Investigate certificates requested through machine templates that contain unexpected Domain Controller identity information.
⚡ Email is still the top attack vector and $3 Billion in BEC losses (2024) proves it.
Modern attacks use AI-written messages, not malware. Traditional filters miss them. Security teams are layering behavioral AI and automation on top of Microsoft 365 to close the gap.
🔗 Learn why email security is shifting to layered defense → https://t.co/BvMXA71MvF
OpenClaw is a powerful personal assistant that can connect to LLMs, integrate with external APIs, and autonomously execute an array of tasks like sending email or controlling browsers.
We developed a deep-dive blog post about what to watch out for and how our platform helps customers identify and secure OpenClaw deployments.
Read more here: https://t.co/kBlIF8ROrF
🔎 Rapid7 Labs, alongside our MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group #LotusBlossom.
Find a deep technical analysis of the custom backdoor 'Chrysalis', Notepad++, Warbird, and more in our latest blog: https://t.co/0JAMmc6WFv
Most exploitation activity related to the CVE-2025-55182 vulnerability affecting React Server Components, Next.js, and related frameworks originated from red teams assessments, but observed exploitation attempts by threat actors deliver various payloads. https://t.co/QG4SgcoqlW
This pre-authentication remote code execution (RCE) vulnerability (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) could allow attackers to execute arbitrary code on vulnerable servers through a single malicious HTTP request.
In this blog, Microsoft Defender researchers share insights and detailed analysis of observed exploitation activity, as well as mitigation, detection, and hunting guidance. Further investigation towards providing stronger protection measures is in progress, and the blog will be updated when more information becomes available.
🛡️ We added 5️⃣ vulnerabilities to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwapzIN & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec
Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices.
The last 3 Cisco advisories are directly tied to this campaign:
- CVE-2025-20333 - RCE (CVSS 9.9)
- CVE-2025-20363 - RCE (CVSS 9.0)
- CVE-2025-20362 - Unauthorized access (CVSS 6.5)
Cisco’s own report details persistence in ROMMON on legacy ASA 5500-X devices without Secure Boot. Attacker activity includes malware implantation, command execution, log tampering, and even crashing devices to block forensics. Cisco links this to the ArcaneDoor threat actor they exposed in 2024.
Cisco advisory listing
https://t.co/Mo8BwvGdIb
Cisco “Continued Attacks Against Cisco Firewalls”
https://t.co/ekJqQGAqzg
CISA Emergency Directive ED 25-03
https://t.co/kJmL9kZ2w4
Admins should treat this as active exploitation, not theoretical risk.
Unauthorized TLS certificates were issued for 1.1.1.1 by a Certification Authority without permission from Cloudflare. These rogue certificates have now been revoked. Read our blog to see how this could affect you. https://t.co/oHbdbLIS8u
Chevron will move its headquarters to Texas from California, the oil company's home state for more than 140 years https://t.co/33AEQX8e27 https://t.co/33AEQX8e27
@UTAustin has officially established a new online learning master’s program in artificial intelligence (AI), with the potential to bring thousands of new students into the field. To read more, visit https://t.co/TWOZI2VroA
Microsoft is still working on a patch for #PrintNightmare, the vulnerability affecting the Windows Print Spooler service. This vulnerability can allow threat actors to remotely execute code with admin-level privileges.
Read more: https://t.co/ZujGDEJGHY