Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
2026-07-20T19:24:10Z•ebd4d8e40543c7e198c54da90ffedc6ca679351359004d71a7114b520ee43d40
ChromeDoSErnst & YoungHuggingFaceOpenSSLPIISonicWallUTA0533WordPresscredentials-compromisedata-breachexploitationmalwarememory-safetypatchthreat-actoruse-after-freezero-day
What happened
Multiple high-impact security stories: SonicWall zero-days CVE-2026-15409 and CVE-2026-15410 were actively exploited by threat actor UTA0533 to deliver custom malware prior to patching. WordPress WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild. OpenSSL patched a ‘HollowByte’ DoS that exhausts server memory via unreleased buffer pre-allocations, and Chrome 150 fixes several critical/high memory safety (use-after-free) bugs. Separately, Hugging Face suffered a production-targeted compromise that exposed internal datasets and service credentials, and an
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- ebd4d8e40543c7e198c54da90ffedc6ca679351359004d71a7114b520ee43d40
- Enrichment time
- 2026-07-20T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.