Top 5 Cybersecurity News Stories July 24, 2026

Cybersecurity News Stories July 24, 2026 — DIESEC editorial header showing five cybersecurity threat icons: OT control panel, firewall UI, server key, workflow dashboard, helpdesk document

The five stories in this week’s Cybersecurity News Stories July 24, 2026 share a structural feature that distinguishes them from the opportunistic exploitation patterns that dominate most news cycles: in each case, the component that was compromised, configured, or exposed was not the primary IT system the organisation considers its attack surface. It was the…

Read More

CVE-2026-50522 SharePoint RCE: Patching Isn’t Enough

CVE-2026-50522 SharePoint RCE

CVE-2026-50522 SharePoint RCE is now the third actively exploited remote code execution flaw hitting Microsoft’s on-premises collaboration platform in three weeks — and this one lets attackers steal cryptographic machine keys that remain valid long after the server is patched. If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, patching is no longer…

Read More

EY Third-Party Data Breach: 15 Days Inside Helpdesk

EY third-party data breach

EY third-party data breach: attackers spent 15 days inside a support-ticketing platform used by Ernst & Young’s tax practice, walking out with client tax filings, Social Security numbers and financial account data before anyone noticed — the firm’s third vendor-side security failure in under three years. What Happened This EY third-party data breach ran from…

Read More

Why Endpoint Protection Isn’t Enough for Modern Small Businesses

Why endpoint protection isn't enough for modern SMEs

Endpoint protection is where most small businesses start their cybersecurity journey — install antivirus or EDR software on every employee laptop, and assume the job is done. After all, if every device is covered, what else is there to protect? The problem is that much of today’s business activity no longer happens solely on those…

Read More

ServiceNow CVE-2026-6875 RCE: Sandbox Escape Exploited

ServiceNow CVE-2026-6875 RCE

ServiceNow CVE-2026-6875 RCE is now being actively exploited: a critical, unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform is under attack barely a week after the vendor shipped a fix, and ServiceNow’s own advisory has not yet caught up with independent confirmation of the exploitation. What Happened ServiceNow CVE-2026-6875 RCE traces back to a sandbox-escape…

Read More