Post

Cybersecurity Newsfeed - 28/07/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 28/07/26

Cybersecurity Newsfeed

📅 28/07/26

🛡️ Vulnerabilities

  • vBulletin Pre-Auth RCE Exploit Released (CVE-2026-61511): A public exploit has been published for a pre-authentication remote code execution flaw in vBulletin’s template engine (v6.2.1 and earlier). The flaw allows unauthenticated users to pass restricted math expressions directly to PHP’s eval function to execute arbitrary OS commands. More info

  • High-Severity n8n Sandbox Escape: Automation platform n8n patched a sandbox escape vulnerability that permitted authenticated workflow editors to bypass JavaScript identifier rewriting via arrow functions and execute operating system commands as the n8n process. More info

  • Certighost Active Directory AD CS Exploit (CVE-2026-54121): A proof-of-concept exploit was released for Certighost, a critical flaw in Windows Active Directory Certificate Services allowing low-privileged authenticated users to hijack domain controller certificates and obtain full administrative rights. More info

  • CISA Adds Fortinet and Arista Flaws to KEV: CISA added Fortinet FortiOS info disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator command injection (CVE-2026-16812) to its Known Exploited Vulnerabilities catalog following active in-the-wild exploitation. More info

🎯 Adversaries

  • macOS ClickFix Campaign Delivers AMOS Stealer: Threat actors are using deceptive fake CAPTCHA verifications (“ClickFix”) to trick macOS users into executing terminal commands that fetch and deploy Atomic macOS Stealer (AMOS) to siphon Keychain entries, browser cookies, and crypto wallets. More info

  • MedusaHVNC Trojan Uses Hidden Desktops: A new malware-as-a-service Remote Access Trojan named MedusaHVNC executes browser sessions on invisible desktop workspaces and injects into charmap.exe to covertly steal data while bypassing behavioral detection. More infoMore info
  • Sextortion Scammers Leverage ShinyHunters Leaks: Cybercriminals are abusing victim email addresses leaked in historical ShinyHunters breaches to demand $2,000 in Bitcoin through fake extortion campaigns alleging device infection and adult content viewing. More info

  • Fake GitHub Repositories Distribute Malware: Attackers are creating malicious GitHub software repositories backed by fake star/fork metrics to trick developers into running code containing embedded supply-chain malware and credential stealers. More info

  • Cruciferra Crypter Uses BYOVD and Process Ghosting: The Mono-based Cruciferra crypter employs API unhooking, Bring Your Own Vulnerable Driver (BYOVD) privilege escalation, and Process Ghosting to run stealthy payloads completely in memory without leaving forensic artifacts on disk. More info

  • SourTrade Malvertising Assembles Payloads In-Browser: The SourTrade campaign bypasses network security and file signatures by delivering raw assembly instructions that construct infostealer binaries directly inside victim browser memory. More info

  • TELESHIM Backdoor Abuses Telegram C2: An East Asian cyber espionage actor targeting Middle Eastern government infrastructure is deploying TELESHIM, a backdoor abusing the Telegram API for C2 communications, alongside the machine-locked BINDCLOAK implant. More info

  • Dysphoria DDoS Botnet Spreads to 200k Devices: A rapidly growing IoT botnet named Dysphoria has infected over 200,000 devices globally. It leverages Solana and Ethereum domain resolving mechanisms for C2 resilience and can launch DDoS attacks exceeding 4 Tbps. More info
  • Daylight Security Launches Detection Program Visibility: Daylight Security introduced a program for Managed Agentic MDR customers that centralizes detection logs across SIEM platforms and maps them directly to the MITRE ATT&CK matrix to highlight operational coverage gaps. More info

  • Proliferation of Unmanaged “Shadow AI” Agents: Employees are actively creating unmanaged AI automations via Microsoft Copilot Studio and Zapier. Possessing persistent permissions without API discovery mechanisms, these agents introduce severe risks of credential exposure and unauthorized access. More info

💥 Breaches & Leaks

  • Apple Sued Over Fake App Store Crypto Wallet: Victims who lost $1.8 million in Bitcoin to a fraudulent Sparrow Wallet application on the iOS App Store have filed a lawsuit against Apple for negligent marketplace screening despite prior warning reports. More info

  • Coca-Cola Confirms Fairlife Ransomware Data Theft: Coca-Cola confirmed that the Anubis ransomware gang exfiltrated 1 TB of data from its Fairlife subsidiary. After the company refused ransom demands, the extortion group published the files online. More info

  • ShinyHunters Claims Ernst & Young Data Breach: The ShinyHunters extortion group claims to have breached EY’s Jira, GitHub, and Azure environments by compromising its IT support ticketing system, threatening to publish client tax and operational data unless paid. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.