AI Security Digest
Aggregated ecosystem risk analysis
Vendor Watchlist
Tracking 0 critical integrations
Threat Stream Feed
Real-time security logs and system alerts
GCP - RESOLVED: Google Cloud VMware Engine (GCVE) Stretched Cluster customers are experiencing zonal outages impacting network connectivity across multiple regions.
Incident began at 2026-07-14 10:00 and ended at 2026-07-14 20:40 (all times are US/Pacific).Preliminary Incident Report We sincerely apologize for the disruption this incident caused to your business. We know how much you rely on Google Cloud, and we regret the impact on your productivity. We are working to address the root cause and prevent this from occurring in the future. Please note, this information is based on our best knowledge at the time of posting and is subject to change as our inve...
Zoom - Service Degradation Affecting Zoom AI Expert Assist in US Region.
Jul 20, 09:55 PDT Resolved - This incident has been resolved and the affected services have been restored. Jul 20, 09:35 PDT Monitoring - Between 07/20/2026 14:38 UTC and 16:01 UTC, a subset of users may have experienced issues affecting Zoom AI Expert Assist in US Region.We have mitigated the issue and our team will continue to monitor the situation closely and keep you informed of any further developments.
Cloudflare - COK (Kochi) on 2026-07-20
Jul 20, 16:45 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 20, 16:30 UTC Scheduled - We will be performing scheduled maintenance in COK (Kochi) datacenter on 2026-07-20 between 16:45 and 18:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location,...
GitHub - Disruption with GPT 5.3 Codex
Jul 20, 16:39 UTC Update - We identified that an upstream provider is returning errors for GPT 5.3 Codex requests, causing some users to experience failed or interrupted responses. Traffic is being automatically rerouted to mitigate impact. We are working with the upstream provider to resolve the underlying issue. We recommend using a different model at this time while we resolve the problem. Jul 20, 16:04 UTC Update - We are investigating GPT Codex 5.3 performance. Jul 20, 16:03 UTC Invest...
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
Hugging Face discloses breach linked to autonomous AI agent
  submitted by   /u/rkhunter_ [link]   [comments]
Sentry - EU Region Error, Attachment, and Feedback latency
Jul 20, 11:41 UTC Identified - We have identified the issue causing errors, attachments, and feedback events to have high ingest latency in our EU region and are working on a fix. Jul 20, 11:11 UTC Investigating - we are investigating an issue affecting errors ingestion in the DE/EU region
Cloudflare - IAD (Ashburn) on 2026-07-20
Jul 20, 11:30 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 20, 09:38 UTC Update - We will be performing scheduled maintenance in IAD (Ashburn) datacenter between 2026-07-20 11:30 and 2026-07-21 06:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this lo...
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of
Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
I’m the researcher credited for CVE-2026-14440. I’m posting here to ask for help pressure-testing the threat model. Cloudflare Universal SSL is the default free automated certificate system for active Cloudflare zones. In the affected configuration, Cloudflare’s authoritative DNS can serve an automatically managed CAA RRset instead of the stricter CAA policy configured by the domain owner, if he/s...
Hugging Face Hacked in Autonomous AI Attack
Targeting production infrastructure, the attack compromised internal datasets and service credentials. https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/   submitted by   /u/sunychoudhary [link]   [comments]
Cloudflare - DXB (Dubai) on 2026-07-20
Jul 20, 09:30 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 17, 09:20 UTC Scheduled - We will be performing scheduled maintenance in DXB (Dubai) datacenter between 2026-07-20 09:30 and 2026-07-22 16:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this l...
Cloudflare - SEA (Seattle) on 2026-07-20
Jul 20, 08:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 17, 09:04 UTC Scheduled - We will be performing scheduled maintenance in SEA (Seattle) datacenter on 2026-07-20 between 08:00 and 13:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this locatio...
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by
Cloudflare - TXL (Berlin) on 2026-07-20
Jul 20, 03:30 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 10:12 UTC Scheduled - We will be performing scheduled maintenance in TXL (Berlin) datacenter on 2026-07-20 between 03:30 and 12:30 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location...
GitHub - Disruption with some GitHub services
Jul 20, 00:26 UTC Update - Some Git LFS operations, and loading files through the API are failing. We are investigating. Jul 20, 00:25 UTC Monitoring - Some Git LFS operations, and loading files through the API are failing. We are investigating. Jul 20, 00:25 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Cloudflare - AMS (Amsterdam) on 2026-07-20
Jul 20, 00:15 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 20, 00:06 UTC Scheduled - We will be performing scheduled maintenance in AMS (Amsterdam) datacenter on 2026-07-20 between 00:15 and 06:30 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this locat...
GitHub - Incident with GitHub Actions
Jul 19, 23:57 UTC Update - We have identified the cause of failures in GitHub Actions and are working to restore service. Jul 19, 23:37 UTC Update - We are investigating degraded availability for GitHub Actions on github.com and in GHEC DR stamps. New workflows may delay or fail to start, and ongoing runs may fail. We will provide more information as soon as we can. Jul 19, 23:34 UTC Investigating - We are investigating reports of degraded performance for Actions
Cloudflare - LHR (London) on 2026-07-19
Jul 19, 23:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 19, 20:34 UTC Scheduled - We will be performing scheduled maintenance in LHR (London) datacenter between 2026-07-19 23:00 and 2026-07-20 06:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this ...
Zoom - Zoom Phone Update - Japan SIP Zones: 7/19/2026 (No Operational Impact)
Jul 19, 08:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 14, 12:08 PDT Scheduled - We will be providing an update to Zoom Phone - Japan SIP zones in Tokyo and Osaka. Please refer to https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0062333 for more details. This update includes a transition to a new call history system.There is no operational impact. All services will be available during this scheduled update.
DigitalOcean - Block Storage Volume NYC1 and NYC3
Jul 19, 09:51 UTC Investigating - Our Engineering team is investigating an issue with attaching volume to the droplets in the NYC1 and NYC3 regions. During this time you may experience an issue with attaching volume to the Droplet(s). We apologize for the inconvenience and will share an update once we have more information.
wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE
Follow-up on the WordPress core pre-auth RCE. Searchlight Cyber held technical details at disclosure and Rapid7 predicted a PoC would land fast. It has. What's new: A working exploit is now public on GitHub, MIT-licensed with an "educational / authorized testing only" disclaimer, and being mirrored on a Telegram channel (bundled with target-discovery dorks). Free, not paywalled. Chain recap: CVE-...
DigitalOcean - Networking in BLR1
Jul 19, 06:57 UTC Investigating - We are currently investigating an issue affecting outbound network traffic for Droplets in the BLR1 region. Customers may experience timeout errors or connectivity issues when attempting to reach external services.Our Engineering team is actively investigating the issue and working to identify the root cause. We will provide additional updates as soon as more information becomes available.
Monday.com - Scheduled Maintenance on the EU Server
THIS IS A SCHEDULED EVENT Jul 19, 05:00 - 06:00 UTC Jul 15, 19:22 UTC Scheduled - On Sunday, July 19th at 05:00 UTC, we will be performing scheduled maintenance on our platform in the EU region. This maintenance is expected to last up to one hour.During this time, monday boards will intermittently be in read-only mode, where actions like creating items, editing boards, creating boards from templates, and changing board permissions will be temporarily unavailable.Thank you for your understanding...
Monday.com - Scheduled Maintenance Across All Regions
THIS IS A SCHEDULED EVENT Jul 19, 05:00 - 06:00 UTC Jul 15, 19:17 UTC Scheduled - On Sunday, July 19th, at 05:00 UTC we will be performing scheduled maintenance on our authentication services across all regions.The maintenance window is expected to last approximately one hour. During this time, users will experience degraded functionality in account & user management. We appreciate your understanding and cooperation during this maintenance.
Zoom - Deprecation of 'Use Content Delivery Network' Feature
THIS IS A SCHEDULED EVENT Jul 18, 17:00 PDT - Jul 19, 17:00 PDT Jun 15, 18:47 PDT Scheduled - We are completing the final phase of the deprecation of the "Use Content Delivery Network" (CDN) feature in Zoom Meetings Web. The UI-side disablement was rolled out last year, and we are now performing a full backend cleanup — removing the remaining codebase and associated database tables.What Is Changing?The backend infrastructure supporting the "Use Content Delivery Network" toggle is being perman...
Zoom - Zoom Phone Update: 7/19/2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Jul 18, 17:00 PDT - Jul 19, 02:00 PDT Jul 14, 11:56 PDT Scheduled - We will be providing an update to Zoom Phone. Please refer to https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0062333 for more details. This update includes a transition to a new call history system.There is no operational impact. All services will be available during this scheduled update.
Cloudflare - Workers and Pages builds stuck intializing.
Jul 18, 21:00 UTC Resolved - Cloudflare is aware of an issue initializing Workers & Pages Builds from 22:05 - 22:45 UTC. The problem has now been resolved.
Cloudflare - Workers and Pages builds unable to start
Jul 18, 16:46 UTC Investigating - Cloudflare is aware of and investigating an issue impacting Workers & Pages Builds from starting. We are working to analyze and mitigate this problem. More updates to follow shortly.
Zoom - Service Degradation Affecting Outbound Calls Audio Quality of Zoom Revenue Accelerator's Auto-Dialer in Japan Region
Jul 18, 07:17 PDT Investigating - We are currently investigating a service degradation affecting outbound calls audio quality of Zoom Revenue Accelerator's auto-dialer in Japan region.Our team is actively working to identify the impact and root cause. We will provide an update as soon as more information becomes available.We appreciate your patience as we work to resolve this issue.
Zoom - Zoom Support Maintenance (July 18, 2026)
THIS IS A SCHEDULED EVENT Jul 18, 07:00 - 08:00 PDT Jul 1, 14:19 PDT Scheduled - We will be performing maintenance on Zoom Support Ticketing and Knowledge Base. Downtime is not expected, but users may experience general slowness for Zoom Support Knowledge Base and Ticketing during the maintenance window.
AWS - Service is operating normally: [RESOLVED] Inaccurate Estimated Billing Data
Between July 16 at 7:38 PM PDT and July 17 at 6:00 AM PDT, customers received erroneous budget and cost anomaly detection alerts, and saw inflated estimated cost and usage data in the Billing and Cost Management Console and the Cost and Usage Reports. These inaccurate billing estimates did not affect customer invoices. On July 16, 2026 at 7:46 PM PDT, our alarms detected cost anomalies but failed to halt the estimated bill generation process or alert our engineering teams. Our engineering team...
Zoom - Service degradation affecting both inbound and outbound calls for a single Provider Exchange partner in the Japan region.
Jul 18, 01:35 PDT Monitoring - The issue affecting both inbound and outbound calls for a single Provider Exchange partner in the Japan region has been successfully resolved.Our team will continue to monitor the situation closely and keep you informed of any further developments. Jul 18, 01:08 PDT Identified - We have successfully identified the root cause affecting both inbound and outbound calls for a single Provider Exchange partner in the Japan region.Our team is actively working on a reso...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to make substantial progress toward resolving the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. Our mitigation efforts are working as expected and we are seeing an increasing number of accounts reflecting correct cost and usage data. We expect all affected accounts to be fully recovered by July 19, 12:00 AM PDT. Until the backfill is complete, some customers may still observe incorrect cost and usage data in the Billing and Cost M...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to make steady progress toward resolving the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. Our efforts to backfill corrected data remain underway, and we expect all affected accounts to be fully recovered by July 19, 12:00 AM PDT. Until the backfill is complete, some customers may still observe incorrect cost and usage data in the Billing and Cost Management Console and Cost and Usage Reports. These estimates do not reflect actual...
GCP - RESOLVED: Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solutions (BMS) services are experiencing a service outage in europe-west4-a due to a cooling failure.
Incident began at 2026-07-15 16:57 and ended at 2026-07-16 05:25 (all times are US/Pacific).Preliminary Incident Report We sincerely apologize for the disruption this incident caused to your business. We know how much you rely on Google Cloud, and we regret the impact on your productivity. Please note, this information is based on our best knowledge at the time of posting and is subject to change as our investigation continues. A final Incident Report with preventative actions will be posted on...
Zoom - Zoom Conference Room Connector DNS Changes: August 16, 2026
Jul 17, 17:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 17, 13:31 PDT Scheduled - As part of ongoing service enhancements for CRC, we are replacing DNS records for SIP/H.323 endpoints in the São Paulo and Mexico regions. Legacy DNS records in some other regions that are no longer in use will be decommissioned.Effective Date: August 16, 2026To avoid service disruption, update your configurations before August 16, 2026.DNS Record...
Zoom - Zoom Contact Center Update: 7/18/2026 (No Operational Impact)
Jul 17, 17:00 PDT In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 14, 11:36 PDT Scheduled - We will be providing an update to Zoom Contact Center. Please refer to https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067626 for more details. This update includes workforce management scheduling and adherence analysis capabilities in CX Analytics.There is no operational impact. All services will be available during this schedu...
Zoom - Zoom Virtual Agent Update: 7/18/2026 (No Operational Impact)
THIS IS A SCHEDULED EVENT Jul 17, 17:00 PDT - Jul 18, 02:00 PDT Jul 14, 11:43 PDT Scheduled - We will be providing an update to Zoom Virtual Agent. Please refer to https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067812 for more details. This update includes a Zoom Virtual Agent Receptionist dashboard.There is no operational impact. All services will be available during this scheduled update.
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the
AWS - Service impact: Inaccurate Estimated Billing Data
Our efforts to backfill corrected estimated cost and usage data are still underway. We are progressing slower than anticipated. While we are seeing some accounts recover with correct cost and usage data, we expect all affected accounts to be recovered by July 19 12:00 AM PDT. Until the backfill is complete, some customers may still see incorrect cost and usage data. The displayed billing estimates do not reflect actual usage and charges. There are no customer actions required at this time. We wi...
1Password - SaaS Manager Workflows are not running as expected
Jul 17, 14:57 EDT Resolved - This incident has been resolved. Jul 17, 14:52 EDT Monitoring - SaaS Manager customers with active workflows may have experienced a service degradation that prevented some workflows from running as scheduled. Our teams quickly identified the issue and implemented a fix. We are now monitoring the recovery to ensure services continue to return to normal.
Cloudflare - NRT (Tokyo) on 2026-07-17
Jul 17, 18:15 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 17, 18:05 UTC Scheduled - We will be performing scheduled maintenance in NRT (Tokyo) datacenter on 2026-07-17 between 18:15 and 21:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location,...
Cloudflare - Cache Reserve users may see increased write errors in the APAC region
Jul 17, 18:11 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 17, 18:06 UTC Investigating - We are investigating an increase in write errors for the R2 cache reserve service
DocuSign - Customers may experience errors loading PowerForms to sign envelopes (Incident 5417)
Jul 17, 17:54 UTC Resolved - The incident has been resolved. Incident duration and timelines are subject to revision pending the results of any related investigation. Jul 17, 17:46 UTC Identified - We have identified the issue and a fix is being implemented. Jul 17, 17:33 UTC Investigating - We are actively investigating this issue.
Supabase - Project Actions Failing Across Multiple Regions
Jul 17, 17:49 UTC Investigating - Certain project actions are failing. We are actively investigating to determine the regions impacted and source of the issue.
Cloudflare - Containers Logs Issues
Jul 17, 17:21 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 17, 16:40 UTC Investigating - A subset of Containers logs for Containers applications that are configured with 'observability.enabled: true' are getting dropped.
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter
Cloudflare - KUL (Kuala Lumpur) on 2026-07-17
Jul 17, 17:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 17, 02:57 UTC Scheduled - We will be performing scheduled maintenance in KUL (Kuala Lumpur) datacenter on 2026-07-17 between 17:00 and 23:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this lo...
AWS - Service impact: Inaccurate Estimated Billing Data
We have identified the root cause and mitigated the underlying issue causing incorrect estimated cost and usage data to be displayed in the Billing and Cost Management Console, and Cost and Usage Reports. We have begun backfilling data to correct cost data for all customers. We expect some customers to begin seeing recovery within the next three hours, and full recovery for all customers by July 18 12:00 PM PDT. Until the backfill is complete, some customers may still see incorrect cost and usag...
MongoDB Atlas - MongoDB Atlas and Atlas for Government: New AWS Backup and AWS Data Transfer costs will be unavailable between July 17 and 20
Jul 17, 16:14 UTC Identified - Due to an ongoing incident with AWS's billing data, MongoDB Atlas and Atlas for Government will not be updating AWS network or backup consumption data over this weekend, 2026-07-17 through 2026-07-20. The products themselves will remain fully available. When the upstream issue has been resolved, we intend to display and bill for the correct amounts. Charges will have usage dates that correctly express the usage, but will have the billed date of when this is correc...
Cloudflare - POST requests not succeeding
Jul 17, 15:50 UTC Identified - The issue has been identified and a fix is being implemented. Jul 17, 15:06 UTC Update - We are continuing to investigate this issue. Jul 17, 15:02 UTC Investigating - Cloudflare is aware of and investigating an issue where some customers may be experiencing POST requests not reaching origin servers correctly. We are working to analyse and mitigate this problem. More updates to follow shortly.
Vercel - Increased invocation failures for Hobby Team functions
Jul 17, 15:19 UTC Resolved - This incident has been resolved.A subset of deployments created under the Hobby plan teams during Jul 17, 2026 10:18 - Jul 17, 2026 14:10 UTC were impacted by this incident. New deployments after this window are unaffected. Jul 17, 14:27 UTC Monitoring - We have deployed a fix and are continuing to monitor. Function invocations for new Hobby Team deployments should no longer fail. If you are still experiencing function invocation errors, redeploy or rollback to a ...
Cloudflare - Cloudflare Workers API Issues
Jul 17, 14:55 UTC Resolved - This incident has been resolved. Jul 17, 14:49 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 17, 14:34 UTC Investigating - Cloudflare is investigating issues when interacting with Workers API and Workers configuration in the dashboard. Customers might experience unexpected errors on Workers endpoints, particularly when deploying a script. Workers that are already running in production are not affected. More updates to follow ...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to work to resolve the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console, including the Cost and Usage Report. The rollback of a recent change did not resolve the issue and we are continuing to investigate multiple mitigation paths. Estimated bill updates remain paused. We are in the process of reverting to the last accurate estimated billing data. The displayed billing estimates do not reflect actual usage and charges. There are no cu...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to work on multiple mitigation paths in parallel to resolve the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. We are evaluating resuming estimated billing computations, as our internal monitoring indicates the billing computation subsystem is now producing accurate estimates. We are conducting additional validation before proceeding with this path. The displayed billing estimates do not reflect actual usage and charges. There are ...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to work to resolve the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. We are actively working on multiple mitigation paths in parallel. The first path involves reverting to the last known good estimated bill computation. With this approach, customers will only see cost and usage data through July 15, however the inflated cost data will be removed. The second path involves rolling back a recent change to the billing computation subs...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to work to resolve the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. As previously shared, we have identified the root cause as an issue with unit pricing within the estimated billing computation subsystem. To prevent further inaccurate billing estimates from being displayed, we have paused estimated billing computations. Customers who are currently seeing normal bill estimates will continue to see those estimates, and customers w...
Cloudflare - Email Delivery Delays
Jul 17, 10:38 UTC Identified - The issue has been identified and a fix is being implemented. Jul 17, 10:10 UTC Investigating - Cloudflare is investigating a delay in our ability to send emails. This includes password reset, mFA token emails. We are working to resolve the issue. More updates to follow shortly.
New Relic - E2M (Events-2-Metrics) authorization issues
Jul 17, 10:21 UTC Resolved - Between 15:00 UTC on July 14th and 10:00 UTC on July 17th, we experienced an issue where some customers experienced authorization issues when attempting to create, read or update E2M (Events-2-Metrics) rules in the US, EU and JP regions. This was due to a recent change we have made to our authorization endpoints. These endpoints now require S2S authentication which has caused requests to our E2M (Events-2-Metrics) to fail. Our teams have rolled back these changes un...
AWS - Service impact: Inaccurate Estimated Billing Data
We continue to work to resolve the issue affecting estimated cost and usage data displayed in the Billing and Cost Management Console. We have identified the root cause as an issue with unit pricing within the estimated billing computation subsystem and we are working on a mitigation. The displayed billing estimates do not reflect actual usage and charges. There are no customer actions required at this time. Once the issue has been mitigated, we expect full resolution to take multiple hours as w...
Cloudflare - Network Performance Issues in Paris, France (CDG)
Jul 17, 09:25 UTC Update - We are continuing to investigate this issue. Jul 17, 08:51 UTC Investigating - Cloudflare is investigating issues with network performance in Paris, France (CDG). A subset of traffic transiting the Paris data center may observe slightly higher latency. We are working to analyse and mitigate this problem. More updates to follow shortly.
AWS - Service impact: Inaccurate Estimated Billing Data
Beginning on July 16 7:38 PM PDT, we began displaying incorrect estimated billing data in the Billing and Cost Management Console. Our engineering teams are engaged and investigating root cause. We will provide another update by 3:00 AM PDT or sooner if more information becomes available.
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the
AWS - Service impact: Inaccurate Estimated Billing Data
We are investigating issues with Cost Explorer reflecting inaccurate estimated billing data.
Cloudflare - SEA (Seattle) on 2026-07-17
Jul 17, 08:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 21:45 UTC Scheduled - We will be performing scheduled maintenance in SEA (Seattle) datacenter on 2026-07-17 between 08:00 and 13:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this locatio...
Cloudflare - Network Performance Issues for AWS ap-northeast-1 region
Jul 17, 07:50 UTC Resolved - This incident has been resolved. Jul 17, 07:44 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 17, 07:36 UTC Identified - The issue has been identified and a fix is being implemented. Jul 17, 07:31 UTC Investigating - Cloudflare is investigating issues with Network Performance for customers using AWS ap-northeast-1 region. Customers may see increased latency and HTTP 5xx errors.We are working to analyze and mitigate this prob...
Cloudflare - CNI 2.0 issues in London
Jul 17, 05:47 UTC Investigating - Cloudflare is currently investigating issues related to CNI 2.0 in London. Customers utilizing CNI 2.0 through London (LHR) data center will experience a failure to send traffic over their CNI. We are working to mitigate impact to CNI customers. More updates to follow shortly.
Akamai - Application Load Balancer reporting availability issues
Jul 17, 04:45 UTC Update - We did not observe a recurrence, and the system looks stable. We continue to monitor to ensure that the impact has been fully mitigated. We will provide the next update as we make progress. Jul 16, 07:27 UTC Monitoring - We have implemented a fix for this issue as of 04:36 UTC on 16 July 2026; based on current observations, the service is resuming normal operations. Customers and partners can find more details on the Akamai Community: https://community.akamai.com/cu...
Cloudflare - Increased HTTP 500 Errors in Querétaro, Mexico
Jul 17, 01:42 UTC Resolved - This incident has been resolved. Jul 17, 01:26 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 17, 01:25 UTC Identified - Cloudflare is investigating an increased level of HTTP 500 errors in Querétaro, Mexico. We are working to analyse and mitigate this problem. More updates to follow shortly.
Cloudflare - IST (Istanbul) on 2026-07-17
THIS IS A SCHEDULED EVENT Jul 17, 01:00 - 14:00 UTC Jul 16, 10:32 UTC Scheduled - We will be performing scheduled maintenance in IST (Istanbul) datacenter on 2026-07-17 between 01:00 and 14:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traffic to fail over els...
Vercel - GitHub-linked deployments and authentication affected
Jul 16, 23:39 UTC Identified - We've identified an issue affecting deployments for projects linked to GitHub repositories, as well as GitHub login, signup, and account connections. CLI deployments and other sign-in methods are unaffected. We will share updates as they become available. Jul 16, 23:09 UTC Investigating - We are investigating elevated error rates for users logging in to Vercel using their GitHub account and connecting their GitHub accounts to Vercel. Login with email or other si...
Cloudflare - LHR (London) on 2026-07-16
Jul 16, 23:30 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 22:37 UTC Scheduled - We will be performing scheduled maintenance in LHR (London) datacenter between 2026-07-16 23:30 and 2026-07-17 06:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this ...
Cloudflare - CDG (Paris) on 2026-07-16
THIS IS A SCHEDULED EVENT Jul 16, 23:00 UTC - Jul 17, 07:00 UTC Jul 15, 14:16 UTC Scheduled - We will be performing scheduled maintenance in CDG (Paris) datacenter between 2026-07-16 23:00 and 2026-07-17 07:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this location, please make sure you are expecting this traff...
GitHub - Degraded REST API Availability
Jul 16, 22:58 UTC Update - API Requests is experiencing degraded performance. We are continuing to investigate. Jul 16, 22:58 UTC Update - We are aware of degraded REST API availability and are investigating Jul 16, 22:51 UTC Investigating - We are investigating reports of impacted performance for some GitHub services.
Box - Issues with Box Edit and Microsoft Office Online
Jul 16, 14:48 PDT Resolved - After further monitoring, this incident is now considered resolved. Microsoft Office Online and Box Edit has been restored to full functionality. Jul 16, 14:47 PDT Monitoring - Our team has taken steps to remediate this issue and is seeing improvement for the Microsoft Online service and Box Edit. Jul 16, 14:45 PDT Identified - Our team has identified the underlying cause of this issue and is working to take remediating steps. Jul 16, 14:30 PDT Update - We are...
Cloudflare - Elevated Errors China Network
Jul 16, 21:47 UTC Investigating - We are investigating an issue with errors in China Network.
GitHub - Claude Fable 5 experiencing degraded performance
Jul 16, 21:06 UTC Update - We are experiencing degraded availability for the Claude Fable 5 model in Copilot products and IDE surfaces. This is due to an issue with an upstream model provider. While we work with them to resolve the issue, we recommend choosing another model or selecting 'Auto' to continue using Copilot. Jul 16, 21:05 UTC Investigating - We are investigating reports of degraded performance for Copilot AI Model Providers
Sentry - Github Integration Webhook processing delay
Jul 16, 21:06 UTC Identified - The issue is mitigated and the webhook backlog is being processed. Seer code reviews will run and linked Github issues and PRs will update incrementally.
Cloudflare - CNI 2.0 Experiencing Intermittent 5XX Errors
Jul 16, 19:47 UTC Monitoring - We have identified and applied a fix for this issue and are currently monitoring the results. Jul 16, 19:07 UTC Investigating - We are currently investigating an issue where customers may experience errors when attempting to view CNI 2.0 interconnections from the API or Dashboard. Data plane traffic is unaffected.
Cloudflare - EWR (Newark) on 2026-07-16
Jul 16, 19:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 09:39 UTC Scheduled - We will be performing scheduled maintenance in EWR (Newark) datacenter between 2026-07-16 19:00 and 2026-07-17 00:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this ...
Cloudflare - BKK (Bangkok) on 2026-07-16
Jul 16, 18:30 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 18:25 UTC Scheduled - We will be performing scheduled maintenance in BKK (Bangkok) datacenter on 2026-07-16 between 18:30 and 22:30 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this locatio...
Supabase - S3 endpoints for keys with special characters broken
Jul 16, 17:55 UTC Identified - We have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.
New Exploitable BOLA Found in Immich (self-hosted media platform)
Full disclosure I'm at Escape but wanted to share something we found that would be interesting to those here! Escape's security research team found a Broken Access Control flaw in Immich which let any user read photos in a locked folder without the required PIN. Immich is a self-hosted media platform with 100k+ stars on GitHub. Their "locked folder" hides sensitive assets behind a PIN-elevated se...
Cloudflare - KUL (Kuala Lumpur) on 2026-07-16
Jul 16, 17:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 16, 12:55 UTC Scheduled - We will be performing scheduled maintenance in KUL (Kuala Lumpur) datacenter on 2026-07-16 between 17:00 and 23:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this lo...
Cloudflare - Durable Objects Increased Errors
Jul 16, 16:53 UTC Update - We are continuing to work on a fix for this issue. Jul 16, 16:49 UTC Identified - The cause of this issue has been identified and a fix is being implemented. Jul 16, 16:44 UTC Update - Cloudflare is investigating issues causing an increase of errors for Durable Objects and downstream services in multiple regions (Europe and APAC). Jul 16, 16:43 UTC Update - We are continuing to investigate this issue. Jul 16, 16:39 UTC Investigating - Cloudflare is investigati...
DigitalOcean - Reserved IP routing in TOR1
Jul 16, 15:30 UTC Identified - Our Engineering team has identified the cause of the issue affecting Reserved IP routing in the TOR1 region, which was causing inbound and outbound traffic to and from Reserved IPs in TOR1 to fail.Detaching and reassigning the Reserved IP to the Droplet may restore connectivity in the meantime. We recommend trying this workaround if you are still experiencing issues with your Reserved IP in TOR1.Our engineering team is now working on implementing a fix. We will pr...
Cloudflare - PDX (Portland) on 2026-07-16
Jul 16, 15:00 UTC In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary. Jul 15, 22:00 UTC Scheduled - We will be performing scheduled maintenance in PDX (Portland) datacenter on 2026-07-16 between 15:00 and 23:00 UTC.Traffic might be re-routed from this location, hence there is a possibility of a slight increase in latency during this maintenance window for end-users in the affected region. For PNI / CNI customers connecting with us in this locati...
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François said in a technical report. "While the number of C2 [command-and-control] domains is currently small, the daily
GCP - RESOLVED: Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solutions (BMS) services are experiencing a service outage in europe-west4-a due to a cooling failure.
Incident began at 2026-07-15 16:57 and ended at 2026-07-16 05:25 (all times are US/Pacific).Summary Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solution (BMS) services experienced a service outage in europe-west4-a due to a cooling failure. Description The datacenter serving europe-west4-a for GCVE, BMS, and NetApp has experienced a power failure, which subsequently caused a cooling failure. Google proactively turned down workloads in order to protect customer...
AWS - Service is operating normally: [RESOLVED] Increased 5xx Errors
Between 12:45 AM and 4:18 AM PDT, we experienced increased 5xx errors for CloudFront customers utilizing VPC Origins connectivity. Our engineers were automatically engaged and immediately began investigating the root cause. By 2:57 AM PDT, we identified the root cause of the issue as an internal constraint on the fleet that manages connections to private VPC origins. When this constraint was reached, the system responsible for distributing routing configuration to our network processors failed t...
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilitie...
NASA Core Flight System (cFS) Health & Safety (HS) Application
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) ...
Cloudflare - Cloudflare Storage Maintenance
THIS IS A SCHEDULED EVENT Jul 16, 12:00 - 13:00 UTC Jul 6, 22:38 UTC Scheduled - Cloudflare has scheduled maintenance for our backend storage systems. Services will continue to operate normally, but customers will be unable to create/delete/modify Client-Side Security settings via the Dashboard or the public API for a period of up to 3 minutes.The following services will experience configuration and new connections limitations during this window:- Client-Side Security (Page Shield)
Cloudflare - Increase in errors for Zone Settings API
Jul 16, 11:57 UTC Resolved - This incident has been resolved. Jul 16, 11:46 UTC Monitoring - A fix has been implemented and we are monitoring the results. Jul 16, 11:37 UTC Update - We are continuing to work on a fix for this issue. Jul 16, 11:22 UTC Identified - The issue has been identified and a fix is being implemented. Jul 16, 11:00 UTC Investigating - Cloudflare has identified issue causing an increase of errors for the Zone Settings API. We are working to analyse and mitigate thi...
AWS - Service impact: Increased 5xx Errors
We continue to see significant signs of recovery as a result of our mitigation efforts, with full recovery expected within the next 45 minutes.
GCP - UPDATE: Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solutions (BMS) services are experiencing a service outage in europe-west4-a due to a cooling failure.
Incident began at 2026-07-15 16:57 (all times are US/Pacific).Summary Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solution (BMS) services experienced a service outage in europe-west4-a due to a cooling failure. Description The datacenter serving europe-west4-a for GCVE, BMS, and NetApp has experienced a power failure, which subsequently caused a cooling failure. Google proactively turned down workloads in order to protect customer data from any risks posed by ...
GCP - UPDATE: Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solutions (BMS) services are experiencing a service outage in europe-west4-a due to a cooling failure.
Incident began at 2026-07-15 16:57 (all times are US/Pacific).Summary Google Cloud VMware Engine (GCVE), Google Cloud NetApp Volumes, and Bare Metal Solution (BMS) services experienced a service outage in europe-west4-a due to a cooling failure. Description The datacenter serving europe-west4-a for GCVE, BMS, and NetApp has experienced a power failure, which subsequently caused a cooling failure. Google proactively turned down workloads in order to protect customer data from any risks posed by ...
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you
AWS - Service degradation: Increased 5xx Errors
We are seeing initial signs of recovery and continue to work toward full recovery.