Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

2026-07-26T08:51:44Z9c6ad29906baa71578cc1f9fd373150147d9e245c1086d78dac4155a9f089877
AI-securityCVE-2025-66376CodeMenderEMEAGoogleHugging FaceKMSLaundry BearMicrosoftRCEServiceNowTPMZimbraaccount-verificationautomotive-vulnerabilitiesdata breachhealthcarephishingransomwaresupply-chain

What happened

Weekly roundup: multiple high-impact incidents and security developments. ServiceNow pre-auth RCE was observed exploited in the wild; Russian state-linked Laundry Bear (TA488) has been exploiting an unpatched Zimbra bug (CVE-2025-66376) to steal emails. Hugging Face reported a breach. Ransomware groups increasingly target the EMEA healthcare supply chain. Microsoft will require TPM-backed attestation for KMS activation; Google released CodeMender (AI-assisted vulnerability detection and patching) and a selfie-video sign-in option; Meta launched a free Facebook Verified badge to combat AI/bot-⁠

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
9c6ad29906baa71578cc1f9fd373150147d9e245c1086d78dac4155a9f089877
Enrichment time
2026-07-26T08:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.