🚨 CISA KEV 1[−]
30 Jul KEVU.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center …SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 12[−]
30 Jul KEVCisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. T…THEHACKERNEWS.COM
30 Jul KEVCisco Secure FMC Zero-Day Exploited in the WildThe vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulRussian hackers turn Exchange flaw into ‘half-click’ mailbox takeoverA Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void B…CSOONLINE.COM
30 JulCisco FMC static credentials exploited by attackers (CVE-2026-20316)A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromis…HELPNETSECURITY.COM
30 Jul KEVCritical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-20…RAPID7.COM
30 JulCVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCVE-2026-54128 Windows DHCP Client Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JulCritical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridgeA critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw, tracke…CSOONLINE.COM
30 JulLaundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The…HELPNETSECURITY.COM
30 JulVU#790363: foreUP golf management platform's web API contains multiple vulnerabilitiesOverview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level au…KB.CERT.ORG
30 JulKindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on RailsOverview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9…RAPID7.COM
30 JulVU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosureOverview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authenticat…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 45[−]
30 JulCISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacksMost IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption. Now, several global agencies are offering a step-by-step action plan, CI Fortify . Releas…CSOONLINE.COM
30 JulExposed credentials are giving attackers a head start many organizations don’t seeCompromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response cap…HELPNETSECURITY.COM
30 JulNothing but the spoof.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
30 Jul KEV200 new CVEs a day and no realistic way to patch them allRyan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’…HELPNETSECURITY.COM
30 JulTop companies to visit at Black Hat USA 2026Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit Day …HELPNETSECURITY.COM
30 JulData breach cost 2026 averaged $4.99 million, AI attacks ran higherMore than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and aimed it somewhere else. Half of breached organizati…HELPNETSECURITY.COM
30 JulRussian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommuni…THEHACKERNEWS.COM
30 JulA Scattered Spider member was indicted. Microsoft’s GDID went to trial.A recently released criminal complaint against Peter Stokes , an alleged member of the Scattered Spider cybercrime group , reveals previously unpublicized details about Windows telemetry . Microsoft has never exactly had a reputation for being privacy-focused, however the complai…CSOONLINE.COM
30 JulAI Scammers Are Better at Building Trust Than HumansResearchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.WIRED.COM
30 JulGoogle Releases Patches for 370 Vulnerabilities in Chrome 151The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flawsINFOSECURITY-MAGAZINE.COM
30 JulChinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksUnit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
30 JulHackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without PromptsSouth Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE b…THEHACKERNEWS.COM
30 JulBuilding secure Uniswap v4 hooksUniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni exploits are two app-level incidents that s…TRAILOFBITS.COM
30 JulAnalog Devices says hackers stole company files in June cyberattackAnalog Devices has disclosed that it suffered a cyberattack in June, resulting in unauthorized access to internal systems and the theft of company files. The semiconductor manufacturer said the incident did not disrupt operations and that it is still investigating the scope of th…CYBERINSIDER.COM
30 JulPortSwigger introduces Burp AT for agentic AI security testingPortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enables penetration testers to delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project conte…HELPNETSECURITY.COM
30 JulCosmosEscape: Taking Over Every Database in Azure Cosmos DBA critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.WIZ.IO
30 JulHHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered EntitiesIn June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reporte…DATABREACHES.NET
30 JulKR: KT Fined 54 Billion Won Over Data Breach via Illegal Base StationsTwo years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damage…DATABREACHES.NET
30 JulMicrosoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsHidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the intern…THEHACKERNEWS.COM
30 JulAI agents gain access to financial workflows amid growing governance gapsAI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizati…CSOONLINE.COM
30 JulNorth Korean hackers behind major open-source supply chain attacks, Amazon saysA North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.THERECORD.MEDIA
30 JulAnalog Devices Discloses Data Breach After Unauthorized System AccessChipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach following a cyberattack that resulted in unauthorized access to some of its s…SECURITYAFFAIRS.COM
30 JulAzure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any DatabaseA now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain b…THEHACKERNEWS.COM
30 JulAI Expands Your Attack SurfaceAI adoption introduces new responsibilities for security teams. Beyond traditional tasks like audits, controls, and awareness training, security leaders must now evaluate AI platforms, data usage, and integrations. AI systems rarely operate alone. Connections to cloud environment…YOUTUBE.COM
30 JulMicrosoft Copilot for Word vulnerable to self-propagating worm-like attackSecurity researcher Håkon Måløy has disclosed a proof-of-concept attack showing how malicious prompts hidden inside Microsoft Word documents can spread between files through Microsoft Copilot for Word. The research suggests that attacker-controlled instructions embedded in one do…CYBERINSIDER.COM
30 JulShadow AI, leadership resistance make AI governance tough for worried CISOsFewer than half of CISOs think their bosses see AI security as a business enabler, according to an Okta survey.CYBERSECURITYDIVE.COM
30 JulRapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor AssessmentIDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is heading. Many security programs are still built around …RAPID7.COM
30 JulCrime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent VectorCrime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to acc…DATABREACHES.NET
30 JulThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesA lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and explo…THEHACKERNEWS.COM
30 JulOkta buys AI security startup Permiso; source says for about $200MThe deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments.TECHCRUNCH.COM
30 JulCanada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure securityCanada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introd…TENABLE.COM
30 JulChrome Needs Twice-a-Week Patching Thanks to AI Bug HuntingThe two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.WIRED.COM
30 JulGoogle says AI helped Chrome fix 1,072 security bugs in two releasesGoogle says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]BLEEPINGCOMPUTER.COM
30 JulShinyHunters claims Brinks Home breach, threatens to leak stolen dataResidential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]BLEEPINGCOMPUTER.COM
30 JulExtend Amazon Inspector SBOM Generator with PluginsAmazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon In…AWS.AMAZON.COM
30 JulFamily says woman violated HIPAA, ‘weaponized’ infoChris Dickerson reports: A medical administrator spent years secretly accessing a family’s medical records and “weaponizing” their private health information for a family dispute, according to a newly filed civil lawsuit. The plaintiffs, identified only by their initials, filed t…DATABREACHES.NET
30 JulCybercriminals Are Leveraging Autonomous AI Offensive Security AgentsResecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barrier…SECURITYAFFAIRS.COM
30 JulCISA issues recommendations to federal agencies on open-source software securityOne expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more. The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop .CYBERSCOOP.COM
30 JulAmazon links Debug, Chalk NPM supply-chain attacks to North Korean hackersAmazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]BLEEPINGCOMPUTER.COM
30 JulAI Harnesses Burst With Potential Exploit OppsA myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.DARKREADING.COM
30 JulWhat water utilities need to know about cybersecurity complianceAs federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities. Key takeaways While the EPA’s national…TENABLE.COM
30 JulA coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities l…CSOONLINE.COM
30 JulSandwich Hats - PSW #937In the security news: - 2.2 million cars, one shared Bluetooth key - JFrog tries to spin an AI 0-day into a win - Sextortion scammers recycling ShinyHunters' leaks - The first hack ever, from 1966 - Prompt injection as a service, $150 a month - Cisco's mystery "static credential"…YOUTUBE.COM
30 JulJetBrains warns of critical TeamCity remote code execution flawJetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]BLEEPINGCOMPUTER.COM
30 JulWhen AI Guardrails Don't MatchA firsthand test showed the same request triggering a safety guardrail in one interface while receiving a normal response through another interface using the same AI model. The discussion suggests implementation differences—such as where guardrails are applied—can lead to inconsi…YOUTUBE.COM
📋 SECURITY BULLETINS 4[−]
30 JulFCC Restricts New Foreign Robots and Inverters Over Security RisksThe FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain …SECURITYAFFAIRS.COM
30 JulAI takes on a bigger role in finding Chrome vulnerabilitiesGoogle has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. “Historically, triaging a single …HELPNETSECURITY.COM
30 JulVMware fixes three critical flaws allowing auth bypass, VM escapesBroadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]BLEEPINGCOMPUTER.COM
30 JulDPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing MalwareThreat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Con…THEHACKERNEWS.COM
📢 SECURITY ADVISORIES 16[−]
30 JulAI’s latest security wake-up call.This week, Dave and Ben discuss two major stories. The first story assess the recent incident where a rogue OpenAI agent escaped its environment and successfully targeted Hugging Face. Additionally, the two also look at an incident where a man was targeted after he reportedly wip…THECYBERWIRE.COM
30 JulNCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network DevicesThe UK’s National Cyber Security Centre wants network device makers to improve forensic observabilityINFOSECURITY-MAGAZINE.COM
30 JulCyber extortionists steal data from UK Department for EducationCybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers.THERECORD.MEDIA
30 JulCISA sets a new SBOM baselineThe US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Admini…HELPNETSECURITY.COM
30 JulTimeless Compliance: Why Better Questions Beat Bigger FrameworksThe best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on Se…SECURITYWEEK.COM
30 JulBuilding a great firewall around AI.China embraces open AI models, then worries it’s become a national security risk. The cyberattack on Minnesota water systems proves larger than first reported. CISA updates its SBOM guidance. AI supercharges dangling DNS attacks. Researchers uncover a self-propagating Copilot wor…THECYBERWIRE.COM
30 JulCISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCsCISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek .SECURITYWEEK.COM
🔥 INCIDENT REPORTING 20[−]
30 JulDealing with AI-Generated ExtortionCombat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence.RECORDEDFUTURE.COM
30 JulAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire SleetAmazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages c…THEHACKERNEWS.COM
30 JulToy Ghouls’ new toy: the GenieLocker ransomwareKaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.SECURELIST.COM
30 JulSrsly Risky Biz: Chipping away at Chinese AI risksTom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let’s not forget that America’s overriding goal is to remain ahead of China in the AI race. There are better ways t…RISKY.BIZ
30 JulCoordinated cyberattack hits more than 30 Minnesota water utilitiesA coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement publis…HELPNETSECURITY.COM
30 JulOpenAI’s Hacking Debacle Was a Human MistakeIf the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.WIRED.COM
30 JulSemiconductor Firm Analog Devices Discloses Data BreachHackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulThe Network Has Become the Control Plane for AI SecurityNetwork firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to…THEHACKERNEWS.COM
30 JulAfter the Break-In: What Attackers Do Once They're Already InsideAttackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove t…BLEEPINGCOMPUTER.COM
30 JulIn the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppableCybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.TECHCRUNCH.COM
30 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnCyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.THERECORD.MEDIA
30 JulHackers abuse Microsoft Teams in ransomware campaign through fake IT supportResearchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.CYBERSECURITYDIVE.COM
30 JulMicrosoft Teams vishing attacks lead to Chaos ransomware attacksThreat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]BLEEPINGCOMPUTER.COM
30 JulAnalog Devices discloses data breach, says operations unaffectedAmerican semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]BLEEPINGCOMPUTER.COM
30 JulChina lists open AI models as national security concern.Cyberattack on Minnesota water systems more extensive than original estimates.THECYBERWIRE.COM
30 JulSemiconductor chip titan Analog Devices reports data breachIn a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.THERECORD.MEDIA
30 JulA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to IranA memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.WIRED.COM
30 JulSouth Korea fines telco giant KT $39 million for customer data breachSouth Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]BLEEPINGCOMPUTER.COM
30 JulClaude uploaded malware to PyPI in Anthropic's botched testOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
30 JulAnthropic's Claude breached 3 orgs, uploaded PyPI malware during testsOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 31[−]
30 JulReconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
30 JulISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
30 JulImpersonation protection: How to protect your executives when the truth isn’t clearHow do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed this dilemma with SVP of Product Matt Covington. Advances in AI, voice, and video impersonation make it difficult to est…HELPNETSECURITY.COM
30 JulProduct showcase: Dashlane Password Manager is more security toolkit than password vaultDashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web …HELPNETSECURITY.COM
30 JulChrome 151 Patches 370 VulnerabilitiesThe major browser update resolves roughly 80 critical- and high-severity security defects. The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulUS and Allies Update SBOM GuidanceFive years after the initial release, the refresh introduces new elements, removes others, and updates terminology. The post US and Allies Update SBOM Guidance appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulNorth Korea’s elite hackers turned on their own government – and got caughtFor years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons progr…BITDEFENDER.COM
30 JulCritical Ruflo Flaw Lets Attackers Spawn Rogue AI SwarmsUnauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek .SECURITYWEEK.COM
30 Jul1 in 5 Data Center Assets Are Within Easy Reach of AttackersClaroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulShould You Use AI for a Task? Here’s a Simple Way to DecideThis essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a was…SCHNEIER.COM
30 JulBlack Hat special: Rewind and revisitAmy looks back at the incredible journeys that brought past guests to the world of threat intelligence.TALOSINTELLIGENCE.COM
30 JulOctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central AsiaOur experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.SECURELIST.COM
30 JulFTC sues Hims & Hers over alleged data privacy and billing violationsThe US Federal Trade Commission, joined by the state of Utah and California, has filed a lawsuit against telehealth provider Hims & Hers, accusing the company of secretly sharing sensitive health information with advertising platforms while misleading customers about its pre…CYBERINSIDER.COM
30 JulDropzone AI turns threat hunting into a routine SOC operationDropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run structured hunt packs across their environments to identify hidden threats, emerging risks, and security coverage gaps that tradition…HELPNETSECURITY.COM
30 JulOrca Security secures AI-built and developer-created applicationsOrca Security has announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep A…HELPNETSECURITY.COM
30 JulAttackers are using Microsoft’s legitimate login system to camouflage phishing attacksAttackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and the second week of July, …HELPNETSECURITY.COM
30 JulCantina Emerges From Stealth With $8 Million in FundingThe startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulOnyx Security Raises $113 Million to Control AI Agents in the EnterpriseThe Series B funding round brings the total raised by Onyx Security to $153 million. The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek .SECURITYWEEK.COM
30 Jul‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global ScaleResearchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulDataBahn Raises $40 Million for Agentic Data Pipeline ManagementThe company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulDiscern Security Raises $13 Million in Series A FundingThe company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulGhanaian national sentenced to 7 years in prison for stealing $10M from romance scam victimsDerrick Van Yeboah impersonated fake romantic partners and directly interacted with victims for more than nine years. The post Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims appeared first on CyberScoop .CYBERSCOOP.COM
30 JulWe know how to protect our troops from telecom attacks. We’re just not doing it.The post We know how to protect our troops from telecom attacks. We’re just not doing it. appeared first on CyberScoop .DEFENSESCOOP.COM
30 JulNovee brings continuous AI pentesting to mobile appsNovee announced the expansion of its AI penetration testing platform to mobile applications. With this addition, Novee becomes the industry’s first complete AI pentesting platform across the modern application attack surface, providing continuous, autonomous coverage. The platfor…HELPNETSECURITY.COM
30 JulAmerican Being Prosecuted for Wiping His Phone Before Handing It Over to Border OfficialsHe’s being prosecuted for giving border officials a code that wiped his phone : The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed…SCHNEIER.COM
30 JulJscrambler launches Unified Client-Side Security PlatformJscrambler launched its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser. “AI didn’t create browser risk—it dramatically accelerated it,” said Rui Ribeiro, …HELPNETSECURITY.COM
30 JulWhat’s new in Microsoft Security: July 2026This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog .MICROSOFT.COM
30 JulOkta to Acquire Identity Threat Detection Firm PermisoThe deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response. The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on Securi…SECURITYWEEK.COM
30 JulOkta’s deal for Permiso aims to close gaps in identity threat detectionEly Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. The post Okta’s deal for Permiso aims to close gaps in identity threat detection…CYBERSCOOP.COM
30 JulBank of America to Acquire Cybersecurity Firm MDSecThe acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek .SECURITYWEEK.COM
30 JulThe State of Network Infrastructure Security 2026The post The State of Network Infrastructure Security 2026 appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
30 Jul'Flying Eagle' Full-Service Mobile RAT Builder Wings Across ChinaA premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.DARKREADING.COM
30 JulCyber threat bulletin: Non-state activity targeting Canadian operational technologyCYBER.GC.CA
30 JulMalwarebytes for Windows, now available on the Microsoft StoreInstall Malwarebytes for Windows from the Microsoft Store with the same full protection and features.MALWAREBYTES.COM
30 JulWhy brand impersonation is becoming an initial access vectorBrand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflar…SECURITYAFFAIRS.COM
30 JulMinnesota Water Utility Attacks Expose Sector's Cyber-RisksA likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.DARKREADING.COM
📡 INFOSEC NEWS 21[−]
30 JulSE Asian Cybercriminal Syndicates Become a Global PowerThe groups move from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.DARKREADING.COM
30 JulIs AI security actually a physical problem?While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them. As Chief Information Security Officer at DataBank, he's watched those data centers go from anonymous…THECYBERWIRE.COM
30 JulFCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber RisksThe Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Prev…THEHACKERNEWS.COM
30 JuleSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis FindsAnalysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users…SECURITYAFFAIRS.COM
30 JulA Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.WIRED.COM
30 JulSilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRATThe Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent…THEHACKERNEWS.COM
30 JulTeams-Themed Phishing Campaign Abused Legitimate Microsoft Login PagesCheck Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructureINFOSECURITY-MAGAZINE.COM
30 JulFTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and SnapThe U.S. federal consumer watchdog said Hims & Hers, which prescribes for sexual wellness and mental health conditions, used website trackers to share customers' information with advertisers.TECHCRUNCH.COM
30 JulHidden prompt turns Microsoft Copilot into an AI wormA new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document.MALWAREBYTES.COM
30 JulAI and Automation Fall Short of Sysadmin ExpectationsAction1 report finds sysadmins overestimated their use of AI in predictions made two years agoINFOSECURITY-MAGAZINE.COM
30 JulHims & Hers sued over alleged health data privacy failuresThe FTC has sued telehealth provider Hims & Hers, alleging it shared customers' sensitive health information with advertisers.MALWAREBYTES.COM
30 JulChinese Open-weight AI Models: Cybersecurity Risks and RewardsChinese models show variation from month to month, highlighting the uncertain and unstable nature of their security postureF5.COM
30 JulClaude Mythos — Hype vs. Reality: What Security Teams Need to KnowIn this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?DARKREADING.COM
30 JulRead This Before You Buy That TV Streaming StickSecurity experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds …KREBSONSECURITY.COM
30 JulGoogle says it fixed more Chrome bugs in June than over the past two years, thanks to AIAs experts have warned for the last two years, some companies — like Microsoft and now Google — are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools.TECHCRUNCH.COM
30 JulRethinking scanning for the AI era: Wiz’s Agentic Code Security SystemEnterprise AI AppSec requires more than powerful models. It requires a system that balances speed, depth, and cost across the software lifecycle.WIZ.IO
30 JulChrome may get faster updates with no restart requiredThe last two versions of Chrome have included more patches than the previous 23 combined.ARSTECHNICA.COM
30 JulOpenAI model was hacking targets for days before being discovered.FTC launches probe into Shein.THECYBERWIRE.COM
30 JulCareCloud begins to notify hundreds of thousands after hackers stole medical recordsThe health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.TECHCRUNCH.COM
30 JulBalancing speed and safety: A control framework for AI coding agentsAI coding agents are part of the developer toolchain. Tools like Kiro and Claude Code generate features, tests, and code refactors from natural-language prompts. A single agent can open dozens of pull requests (PRs) across your repositories in an afternoon. That productivity come…AWS.AMAZON.COM
30 JulResearchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police AppResearchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau …SECURITYAFFAIRS.COM