News Jul 9, 2026 👁 22

IT News Roundup: Gitea Exploitation, Device Code Phishing Surge, AI Superconductivity Discovery - July 9 2026

This week's IT news covers rapid exploitation of a critical Gitea vulnerability, a massive spike in Microsoft 365 device code phishing attacks, a Linux kernel VM escape flaw, and an AI-driven breakthrough in superconductor research.

The first half of July 2026 has delivered a wave of active exploit campaigns targeting widely deployed infrastructure, alongside significant developments in AI research and open-source security. Attackers are moving fast on newly disclosed vulnerabilities, while the AI sector continues its rapid evolution with both commercial releases and scientific breakthroughs.

Gitea Authentication Bypass Vulnerability Under Rapid Exploitation

Security researchers have confirmed active exploitation of a critical authentication bypass vulnerability in Gitea, a popular self-hosted Git service. The flaw, tracked as CVE-2026-20896, allows attackers to bypass authentication entirely using a single HTTP header, granting unauthorized access to repositories and exposed secrets.

The vulnerability has been exploited at speed, with threat actors scanning the internet for vulnerable Gitea instances and extracting credentials, source code, and API tokens from exposed repositories. Organizations running self-hosted Gitea instances are urged to patch immediately or restrict external access to their instances as an interim measure.

Source: SecurityWeek

Microsoft 365 Device Code Phishing Campaigns Surge 37x

A Microsoft 365 device code phishing campaign has been observed at unprecedented scale, with detection rates spiking 37 times their previous levels. Between late June and early July, attackers leveraged collaboration-themed lures to compromise victim accounts, and the tactic has now been adopted by 18 different phishing kits and every major Access-in-the-Middle (AiTM) vendor.

Device code phishing works by directing victims to a Microsoft login page where they enter a code displayed on the attacker's machine, effectively granting the attacker a valid session token. The campaign has shifted device code phishing from an espionage-grade technique to a criminal commodity, with attackers using it to bypass traditional multi-factor authentication protections.

Source: The Hacker News / BleepingComputer

Linux Kernel VM Escape Vulnerability Threatens KVM Isolation

A Januscape-disclosed Linux kernel vulnerability enables virtual machine escape on both Intel and AMD systems, breaking KVM guest-to-host isolation boundaries. The flaw affects a wide range of virtualization deployments and could allow a compromised guest VM to execute arbitrary code on the host system.

For organizations running KVM-based virtualization — including many homelab and cloud infrastructure setups — this represents a significant risk. Any workload running in a guest VM could potentially be used as an attack vector to compromise the entire host. Patches have been released for affected kernel versions, and system administrators are advised to update promptly.

Source: Hendry Adrian Cybersecurity Daily Recap

SharePoint Server RCE Added to CISA KEV After Active Exploitation

CISA has added CVE-2026-45659, a remote code execution vulnerability in SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation in the wild. U.S. federal agencies were required to remediate the vulnerability by July 4, 2026, and all organizations running SharePoint Server should prioritize patching immediately.

The vulnerability allows unauthenticated attackers to execute arbitrary code on affected SharePoint servers, potentially leading to full network compromise. The addition to KEV signals that exploitation tools and techniques have matured beyond proof-of-concept stage and are being used in targeted attacks against enterprise environments.

Source: The Hacker News

Nissan Confirms Employee Data Breach via Oracle PeopleSoft Zero-Day

Nissan Motor Corporation confirmed it was among the victims of the ShinyHunters threat group's Oracle PeopleSoft zero-day campaign (CVE-2026-35273). The breach exposed sensitive personal and financial data for current and former employees across four countries: the United States, Canada, Mexico, and Brazil.

The ShinyHunters group has been actively targeting enterprise ERP systems since early 2026, exploiting unpatched vulnerabilities in Oracle PeopleSoft to extract sensitive data. Organizations running Oracle PeopleSoft should verify their systems are patched against CVE-2026-35273 and monitor for signs of compromise including unusual data exports and unauthorized administrative access.

Source: IT Briefcase

Black Duck OSSRA 2026: Open Source Vulnerabilities Double as AI Adoption Soars

The 2026 Open Source Security Risk Analysis (OSSRA) report from Black Duck reveals that the average number of open-source vulnerabilities per codebase has doubled to 581, driven by the explosive growth in AI adoption. The report found that 87% of codebases are now at risk, with 65% having been hit by attacks.

The surge in vulnerabilities correlates directly with the proliferation of AI development tools and frameworks, which tend to pull in large numbers of dependencies. The report underscores the need for automated dependency monitoring and regular vulnerability scanning as part of standard development workflows, particularly for projects incorporating AI components.

Source: Black Duck Blog

AI and Machine Learning Discover New Room-Temperature Superconductors

In a significant scientific breakthrough, researchers have combined machine learning with quantum physics to discover two new superconductors and create a much faster method for searching for additional candidates. The technique could bring scientists significantly closer to the long-sought goal of room-temperature superconductivity.

The method addresses a longstanding challenge in scientific AI, where high-order derivative computations in noisy real-world data tend to fail. Applications span genomics, materials science, climate modeling, and chromatin biology. The findings are set to appear in Transactions on Machine Learning Research and will be presented at NeurIPS 2026, signaling growing confidence in AI-driven materials discovery.

Source: ScienceDaily


← Back to Blog