July 21, 2026 by sig9

Hacker Wars - July 21, 2026

bulletin-feature-image

Your daily dose of infosec chaos


Newly disclosed flaws are getting weaponized at record speed, with attackers cashing in before defenders even finish reading the advisories. Ransomware crews have figured out that AI model weights make lovely kidnap targets, and a fresh Windows zero-day just got an unofficial patch before the vendor could ship one. Another day, another reminder that “patch within 30 days” is a fantasy timeline.

Critical ServiceNow AI Platform Flaw Exploited In The Wild

A critical ServiceNow AI Platform vulnerability (CVE-2026-6875, CVSS 9.5) allowing sandbox escape and unauthenticated remote code execution is being actively exploited within days of disclosure. The gap between patch and weaponization has essentially collapsed to zero, so if you are not already patched, you are late.

What to do: Patch your ServiceNow instances immediately and hunt logs for signs of sandbox escape or unexpected code execution.


ENCFORGE Ransomware Encrypts AI Model Weights In Langflow Attacks

Researchers linked a second attack on a Langflow server to JADEPUFFER, an AI-agent-driven operator now deploying ENCFORGE, a compiled Go ransomware that encrypts AI model weights and vector indexes. Turns out your expensive trained models are now hostage material, and nobody thought to back up the weights.

What to do: Isolate any internet-facing Langflow instances, back up model artifacts offline, and hunt for ENCFORGE encryption activity.


Estée Lauder Breached Through Oracle E-Business Suite Flaw

Cosmetics giant Estée Lauder is notifying customers after attackers exploited a vulnerability in Oracle E-Business Suite the company used for HR operations. Yet another reminder that your ERP is a breach waiting to happen, especially when it is exposed to the internet.

What to do: Inventory any internet-facing Oracle E-Business Suite deployments and apply the relevant patches before you write your own notification letter.


Windows LegacyHive Zero-Day Enables Privilege Escalation

A newly disclosed Windows zero-day dubbed LegacyHive lets attackers escalate privileges on fully patched systems, with free unofficial patches already available from third-party researchers. When the community ships a fix before the vendor, you know the timeline is awkward.

What to do: Evaluate the unofficial 0patch fix for high-risk hosts and watch for Microsoft’s official patch in next month’s update.


Zimbra Patches Critical Command Injection And SSRF Flaws

Zimbra’s latest refresh closes a batch of critical flaws spanning command injection, XSS, authentication bypass, and SSRF across its collaboration suite. Email and collaboration platforms remain a favorite initial access vector, so this is not the update to sit on.

What to do: Update Zimbra to the latest build and review mail server logs for signs of prior exploitation.


That’s the chaos for today. Stay sharp out there.


Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown

This bulletin is provided for informational purposes. Contact us for tailored security analysis.