Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
Continue reading Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.
The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.
Continue reading Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.
The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.
Continue reading Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
Continue reading Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
Continue reading SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch