INTEL_REPORT
The Hacker News · published 7/20/2026, 9:10:56 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the New 7-…
https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
sha256:790dc1cb663dfe3360398b75eb7334a9683c394786a0f69d20a6eaba84c99623
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.