Cybersecurity Newsfeed - 28/07/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 28/07/26
🛡️ Vulnerabilities
vBulletin Pre-Auth RCE Exploit Released (CVE-2026-61511): A public exploit has been published for a pre-authentication remote code execution flaw in vBulletin’s template engine (v6.2.1 and earlier). The flaw allows unauthenticated users to pass restricted math expressions directly to PHP’s
evalfunction to execute arbitrary OS commands. More infoHigh-Severity n8n Sandbox Escape: Automation platform n8n patched a sandbox escape vulnerability that permitted authenticated workflow editors to bypass JavaScript identifier rewriting via arrow functions and execute operating system commands as the n8n process. More info
Certighost Active Directory AD CS Exploit (CVE-2026-54121): A proof-of-concept exploit was released for Certighost, a critical flaw in Windows Active Directory Certificate Services allowing low-privileged authenticated users to hijack domain controller certificates and obtain full administrative rights. More info
CISA Adds Fortinet and Arista Flaws to KEV: CISA added Fortinet FortiOS info disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator command injection (CVE-2026-16812) to its Known Exploited Vulnerabilities catalog following active in-the-wild exploitation. More info
🎯 Adversaries
macOS ClickFix Campaign Delivers AMOS Stealer: Threat actors are using deceptive fake CAPTCHA verifications (“ClickFix”) to trick macOS users into executing terminal commands that fetch and deploy Atomic macOS Stealer (AMOS) to siphon Keychain entries, browser cookies, and crypto wallets. More info
Sextortion Scammers Leverage ShinyHunters Leaks: Cybercriminals are abusing victim email addresses leaked in historical ShinyHunters breaches to demand $2,000 in Bitcoin through fake extortion campaigns alleging device infection and adult content viewing. More info
Fake GitHub Repositories Distribute Malware: Attackers are creating malicious GitHub software repositories backed by fake star/fork metrics to trick developers into running code containing embedded supply-chain malware and credential stealers. More info
Cruciferra Crypter Uses BYOVD and Process Ghosting: The Mono-based Cruciferra crypter employs API unhooking, Bring Your Own Vulnerable Driver (BYOVD) privilege escalation, and Process Ghosting to run stealthy payloads completely in memory without leaving forensic artifacts on disk. More info
SourTrade Malvertising Assembles Payloads In-Browser: The SourTrade campaign bypasses network security and file signatures by delivering raw assembly instructions that construct infostealer binaries directly inside victim browser memory. More info
TELESHIM Backdoor Abuses Telegram C2: An East Asian cyber espionage actor targeting Middle Eastern government infrastructure is deploying TELESHIM, a backdoor abusing the Telegram API for C2 communications, alongside the machine-locked BINDCLOAK implant. More info
- Dysphoria DDoS Botnet Spreads to 200k Devices: A rapidly growing IoT botnet named Dysphoria has infected over 200,000 devices globally. It leverages Solana and Ethereum domain resolving mechanisms for C2 resilience and can launch DDoS attacks exceeding 4 Tbps. More info
📈 Trends
Daylight Security Launches Detection Program Visibility: Daylight Security introduced a program for Managed Agentic MDR customers that centralizes detection logs across SIEM platforms and maps them directly to the MITRE ATT&CK matrix to highlight operational coverage gaps. More info
Proliferation of Unmanaged “Shadow AI” Agents: Employees are actively creating unmanaged AI automations via Microsoft Copilot Studio and Zapier. Possessing persistent permissions without API discovery mechanisms, these agents introduce severe risks of credential exposure and unauthorized access. More info
💥 Breaches & Leaks
Apple Sued Over Fake App Store Crypto Wallet: Victims who lost $1.8 million in Bitcoin to a fraudulent Sparrow Wallet application on the iOS App Store have filed a lawsuit against Apple for negligent marketplace screening despite prior warning reports. More info
Coca-Cola Confirms Fairlife Ransomware Data Theft: Coca-Cola confirmed that the Anubis ransomware gang exfiltrated 1 TB of data from its Fairlife subsidiary. After the company refused ransom demands, the extortion group published the files online. More info
ShinyHunters Claims Ernst & Young Data Breach: The ShinyHunters extortion group claims to have breached EY’s Jira, GitHub, and Azure environments by compromising its IT support ticketing system, threatening to publish client tax and operational data unless paid. More info
