The Russian state-sponsored hacking group tracked as Laundry Bear (Void Blizzard, TA488) is exploiting CVE-2026-42897, a zero-day cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA). The flaw allows attackers to execute malicious JavaScript when a victim opens a specially crafted email, enabling the deployment of the OWAReaper backdoor.
The campaign has targeted government agencies and organizations across the US and Europe, including the telecommunications, finance, hospitality, and aerospace sectors. The vulnerability stems from improper HTML sanitization in email messages.
Cisco has warned that a high-severity vulnerability in Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, is being actively exploited as a zero-day. The flaw is caused by built-in static credentials for a low-privilege account, allowing remote attackers to gain unauthorized access and view sensitive data. Cisco says it became aware of active exploitation in July 2026 but has not shared any further details.
Hackers are exploiting a security flaw in the FastJson Java library that allows to run malicious code remotely without user action. The vulnerability affects FastJson versions 1.2.68 to 1.2.83 and has been used to target organizations in the US across industries such as finance, healthcare, retail, and technology.
Arista has fixed a critical actively exploited vulnerability (CVE-2026-16812) in on-premises VeloCloud Orchestrator (VCO) deployments. The flaw is an unauthenticated OS command injection vulnerability. Arista has not yet disclosed details about the attacks, the threat actors involved, or the specific exploitation method.
Broadcom has released security updates for multiple VMware vulnerabilities affecting ESX, vCenter, Workstation, and Fusion. The fixes include three critical flaws in vCenter and ESX that could allow authentication bypass, arbitrary code execution, information disclosure, or denial of service.
JetBrains has warned about a security flaw in TeamCity On-Premises (CVE-2026-63077) that allows attackers with HTTPS access to bypass authentication and remotely execute commands on affected servers. The vulnerability impacts all TeamCity On-Premises versions. TeamCity Cloud users do not need to take action.
JFrog confirmed that OpenAI's AI models exploited previously unknown flaws in self-hosted Artifactory servers to escape a restricted testing environment and gain internet access. After escaping, the models used additional exploits and stolen credentials to compromise Hugging Face's production infrastructure while attempting to obtain cybersecurity benchmark answers. The vulnerable package-registry proxy was later identified as a self-hosted JFrog Artifactory installation.
In an update, OpenAI said its AI models used publicly exposed login credentials to access four third-party services during the Hugging Face security incident. One account was used to help route and store attack-related data, while the other two were only viewed. OpenAI has not identified the services or found evidence that the AI agent caused further damage or compromised additional accounts.
Following the disclosure, Anthropic revealed that during internal security testing, one of its Claude models created a malicious Python package and uploaded it to PyPI, where it ran on 15 real systems before it was removed. The company said this was one of three controlled evaluation incidents in which experimental Claude models, running without Anthropic's usual production safeguards, reached the open internet and compromised test production infrastructure.
The China-linked Silver Fox cybercrime group has been observed using vulnerable drivers and legitimate applications to bypass security defenses and attack a Japanese industrial manufacturing organization. The attackers deployed ValleyRAT (Winos 4.0), a malware tool that provides long-term remote access, and leveraged multiple techniques to hide malicious activity and maintain control of infected systems.
South Korean authorities released a joint advisory detailing a state-sponsored intrusion that compromised trusted websites to spread malware. The attackers exploited a vulnerable financial security software called AnySign4PC to install backdoors (SIGNBT and COPPERHEDGE) on visitors’ systems without user action. KISA advises users with affected AnySign4PC versions (1.1.4.4–1.1.4.6) to update to version 1.1.5.0.
Amazon linked several major npm supply chain attacks to the North Korean threat actor, tracked as Sapphire Sleet (BlueNoroff/Stardust Chollima). The attackers compromised popular packages, including typo-crypto, debug, chalk, and axios, by tricking package maintainers and publishing malicious updates that spread to users automatically. Amazon believes the early typo-crypto attack in March 2025 was a test before larger attacks in September that affected many cloud environments. The campaign appeared financially motivated, using trusted open-source packages to reach a large number of victims at once.
Hackers launched a coordinated cyberattack against more than 30 community water systems in Minnesota, the US, on July 26–27. The attacks targeted water utility computer systems, causing outages, equipment issues, and temporary disruptions. Authorities activated cybersecurity response teams, while affected communities switched to manual operations and backup plans to keep water services running.
On the same note, the US and Australian governments have released new cybersecurity guidance that provides recommendations for disconnecting critical operational technology (OT) environments and associated systems from corporate networks, Internet-facing connections, and other less-trusted networks to ensure continuity of critical services in the event of a cyberattack.
Separately, the US government and 13 allied countries issued updated guidance defining the minimum information an SBOM (Software Bill of Materials, a list of the software components used in a software product) should include. The goal is to improve software transparency, identify security risks, and help organizations manage software supply chain security.
A threat actor has used the open-source Hermes AI agent to automate post-exploitation tasks during a suspected intrusion involving Thailand's Ministry of Finance. Researchers found exposed web directories on a Hong Kong-based server that contained 585 files totaling about 470 MB, including exploit code, web shells, tunneling tools, custom scripts, stolen credentials, malware payloads, and logs generated by the Hermes AI agent.
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign has been active since at least June and has affected organizations in industries including finance, healthcare, legal, energy, retail, and professional services.
Cybersecurity researchers have discovered a phishing campaign that pretends to be a Microsoft Teams update to trick users into giving attackers remote access to their computers. Victims are sent to a fake Microsoft Store page that claims Teams must be updated before they can open the shared file. Instead of installing an update, the download launches a hidden PowerShell command that installs legitimate remote monitoring and management (RMM) software, including Level RMM and ConnectWise ScreenConnect.
In an unrelated campaign, a threat actor believed to be operating as an initial access broker for ransomware groups has been observed targeting organizations via Microsoft Teams vishing attacks. After gaining access, the attackers use PowerShell scripts to collect system information, identify antivirus and endpoint detection tools, fingerprint corporate environments, and deliver additional malware. The main payload is a Go-based backdoor named GoGRPC.
Cybersecurity researchers at QiAnXin XLab have discovered a botnet called Dysphoria that has infected around 200,000 devices worldwide. The malware is used for distributed denial-of-service (DDoS) attacks and network traffic relay operations.
Australian drone technology company CubePilot was hit by a cyberattack when hackers took control of its DNS records and redirected visitors to fake websites. The fake sites had valid HTTPS certificates, meaning some users’ login details and other information may have been stolen. CubePilot has restored its website, cancelled the fake certificates, and reported the incident to cybersecurity authorities and police. Customers are advised to change reused passwords and avoid installing firmware downloaded between July 24 and July 25 until CubePilot confirms it is safe. Firmware downloaded before July 24 is considered secure.
Europol has flagged 4,340 URLs for removal following a multi-week operation targeting online content linked to ‘The Com,’ a decentralized network of nihilistic violent extremist groups. Authorities identified content including violent videos, self-harm and suicide material, child sexual abuse content, animal cruelty, violent attacks, and manuals promoting crimes such as murder, grooming, improvised explosives, doxing, and swatting.