Empirical Security Raises $25 Million in Series A Funding
2026-07-21T13:24:06Z•a34d50ae2eab96e0d89f1dd664cb31bf58634aebe69e2013884adde561bf89b9
C2CVE-2026-6875Clover HealthEstée LauderHollowGraphMetaMicrosoft 365Oracle EBSSSRFServiceNowXSSZimbracalendarcommand injectiondata breachincident disclosuremalwareremote code executionsecurity patchingsocial engineeringvulnerabilityzero-day
What happened
This feed contains multiple high-impact security items: new HollowGraph malware that uses compromised Microsoft 365 calendars as a two-way C2 dead-drop; active exploitation of a ServiceNow AI platform vulnerability tracked as CVE-2026-6875 enabling remote code execution; a Zimbra update addressing multiple critical flaws (command injection, XSS, restriction bypass, SSRF); and an Oracle E-Business Suite zero-day used to exfiltrate personal, financial and health data from Estée Lauder. Other items include a Clover Health data breach via social engineering, a Meta broken access control bounty, Io
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- a34d50ae2eab96e0d89f1dd664cb31bf58634aebe69e2013884adde561bf89b9
- Enrichment time
- 2026-07-21T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.