Cybersecurity Headlines — July 22, 2026


From the Trenches

As a cybersecurity practitioner, I’ve been keeping an eye on recent developments that should keep me up at night. The first interesting story that caught my attention is the data breach disclosed by Estée Lauder via Oracle E-Business flaw. This highlights how even large companies with seemingly robust security measures can be vulnerable to exploitation through third-party software vulnerabilities. It’s a stark reminder for organizations to conduct thorough vulnerability assessments and patch management.

The second story that resonated with me is the ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875). As a practitioner, I’ve seen firsthand how quickly exploits can spread across the internet. This particular exploit takes advantage of a pre-authentication remote code execution vulnerability in ServiceNow, making it a high-priority target for attackers. It’s essential for organizations using ServiceNow to patch this vulnerability as soon as possible.

🔧 Patch Priority: CVE-2026-6875 should be patched immediately due to its potential for widespread exploitation.


Compiled daily. Stay patched, stay vigilant.