Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 18:19 23/07/2026 UTC
  • Vulnerability H score 83 Linux kernel XFS reflink local root flaw (CVE-2026-64600) Qualys disclosed the RefluXFS XFS reflink local root flaw (CVE-2026-64600) after its model found a Dirty COW-like race, advancing exposure as highly reliable, log-silent persistent-root local exploitation becomes possible.
  • Vulnerability H score 49 Langflow unauthenticated RCE flaw (CVE-2026-0770) Trend Micro traced CVE-2026-0770 exploitation to Langflow’s /api/v1/validate/code endpoint, reinforcing immediate patch urgency because the bug is unauthenticated RCE as root and already being exploited.
  • Public Sector Action H score 37 CISA BOD 26-04 patch directive for CVE-2026-16232 CISA added CVE-2026-16232 to KEV and issued a BOD 26-04 patch deadline for SmartConsole servers, turning a known exploited issue into a federal remediation timeline.
  • Incident H score 44 Upbound Group hit by ransomware attack Upbound Group disclosed a breach where stolen customer data enabled fraudulent Acima agreements and about $13M in losses, updating the case from compromise to confirmed financial abuse.
  • Exploitation Wave H score 42 SharePoint exploitation wave CISA warned that SharePoint attacks have expanded to a fourth case in a month, increasing risk for exposed SharePoint instances even as CVE-2026-50522 was not yet in KEV.
Last updated: 07:34 23/07/2026 UTC

Latest updates

Browse →

UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine

Campaign

Updated: 23.07.2026 19:32 · First: 23.07.2026 19:32 · 📰 1 src / 1 articles · H score: 33

The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in Ukraine. The chain uses Evernote.zip with a legitimate Notepad++ 8.8.3 copy and NppExport.dll, then unpacks loaders such as BurnyBear and MatchBoil V2. The activity is tied to a cluster previously linked to initial access for APT44 / Sandworm, and it does not rely on a software exploit or supply-chain compromise.

CERT-UA update advice for Notepad++, 7-Zip, and WinRAR

Advisory/Mitigation

Updated: 23.07.2026 19:32 · First: 23.07.2026 19:32 · 📰 1 src / 1 articles · H score: 15

CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known flaws and reduces the risk of malicious plugin loading and related abuse in affected environments. The advisory is tied to a live attack pattern against systems used by organizations in Ukraine.

TriBack Loader DLL sideloading delivery activity

Malware Activity

Updated: 23.07.2026 15:20 · First: 23.07.2026 15:20 · 📰 1 src / 1 articles · H score: 17

TriBack Loader appeared in four DLL sideloading infection chains, expanding a Windows loader operation that delivered post-exploitation payloads and increased the risk of follow-on compromise. Two builds carried AdaptixC2, and another used DonutLoader to launch Beagle, showing that the loader was used to stage multiple payload types across separate chains. The activity also left defenders with concrete detection cues, including signed executables, malicious DLLs, and encrypted companion files in user-writable or Startup locations.

Linux kernel XFS reflink local root flaw (CVE-2026-64600)

Vulnerability

Updated: 23.07.2026 11:04 · First: 23.07.2026 11:04 · 📰 2 src / 2 articles · H score: 83

CVE-2026-64600 is a Linux kernel XFS reflink race condition, dubbed RefluXFS by Qualys TRU, that can let an unprivileged local user overwrite root-owned files and gain persistent root access. The flaw affects XFS with reflink enabled on Linux kernel v4.11 or later, including major enterprise Linux deployments, and Qualys says exploitation is highly reliable, leaves no kernel log output, and can survive a reboot. The issue was introduced in February 2017, patched upstream on July 16, and vendors have started shipping backported fixes. Red Hat, Debian, and other Linux vendors have listed affected package streams, while Qualys estimates the exposure could exceed 16.4 million systems based on its asset analysis.

Operation Muck and Load GitHub malware-delivery cluster

Malware Activity

Updated: 23.07.2026 14:28 · First: 23.07.2026 14:28 · 📰 1 src / 1 articles · H score: 29

Operation Muck and Load has expanded a GitHub repository network into a malware-delivery channel, putting 200 repositories across 190 accounts behind the spread of Windows-based malware. The activity matters because the repositories are not just lures; they also distribute payloads through GitHub release assets and embedded content. The payload mix includes information stealers, loaders, downloaders, droppers, spyware, remote access trojans, and Monero miners.

Dolphin X Windows infostealer and RAT with AI victim profiling

Malware Activity

Updated: 23.07.2026 13:19 · First: 23.07.2026 13:19 · 📰 1 src / 1 articles · H score: 29

The newly discovered Dolphin X malware is using AI-powered profiling to rank infected users and steer attackers toward higher-value victims, improving theft efficiency across a broad Windows target set. It is built as a Windows infostealer and RAT that targets more than 300 applications and steals credentials and sensitive files, including cryptocurrency wallets, .env files, SSH keys, cloud tokens and DevOps credentials. The operator’s scoring system gives criminals a fast way to separate low-value infections from machines likely to provide better access or data.

Google Account selfie video sign-in and recovery

Security Tool/Service

Updated: 23.07.2026 13:00 · First: 23.07.2026 13:00 · 📰 1 src / 1 articles · H score: 11

Google introduced an opt-in selfie video sign-in and account-recovery method for Google Accounts. Users can enroll by recording a short face video with guided head movements, then later use a fresh selfie video to verify identity and regain access when locked out. The feature stores data encrypted at rest, can be deleted from the account, and is unavailable for Google Workspace, Child accounts, and accounts in the Advanced Protection Program.

MsaRAT backdoor routes C2 through Chrome or Edge

Malware Activity

Updated: 23.07.2026 12:59 · First: 23.07.2026 12:59 · 📰 2 src / 2 articles · H score: 23

Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos says the implant uses CDP to drive the browser, then relays traffic through Cloudflare Workers and Twilio TURN so the attacker’s server IP does not appear directly on the wire. The delivery chain starts with curl.exe fetching a fake Windows update MSI from 172.86.126[.]18:443, which loads lib.dll in memory before the encryptor runs.

Microsoft Exchange Online mailbox quarantine disruption after infrastructure change

Service Disruption

Updated: 23.07.2026 12:20 · First: 23.07.2026 12:20 · 📰 1 src / 1 articles · H score: 0

A Microsoft Exchange Online service disruption is mistakenly quarantining customer mailboxes, blocking email delivery and calendar access for affected users. The issue is tracked as EX1436407 and began on July 19. Microsoft tied the problem to a recent infrastructure change that caused excessive memory consumption and an out-of-memory condition. Remediation is underway, with mailboxes being removed from quarantine as cleanup progresses.

SmartConsole actively exploited authentication bypass (CVE-2026-16232)

Vulnerability

Updated: 23.07.2026 11:13 · First: 23.07.2026 11:13 · 📰 2 src / 2 articles · H score: 34

Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products. The flaw can let an attacker obtain an application login token, then use full administrator privileges to change security policy and configuration on exposed management environments. Check Point said the issue was observed in the wild against a limited number of customers whose management environments were directly exposed to the Internet without IP restrictions. CISA added the CVE to its KEV catalog and set a July 25 deadline for U.S. federal agencies, while Check Point released patches, mitigations, and IoCs.

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action

Updated: 23.07.2026 11:13 · First: 23.07.2026 11:13 · 📰 1 src / 1 articles · H score: 37

CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25. The directive makes Binding Operational Directive (BOD) 26-04 immediately relevant for exposed management servers. The action turns an actively exploited flaw into a federal remediation deadline and increases pressure on other organizations to patch quickly.

AI is increasing ransomware effectiveness against ransomware-hit organizations

Trend

Updated: 23.07.2026 11:00 · First: 23.07.2026 11:00 · 📰 1 src / 1 articles · H score: 26

A Proofpoint survey found AI is making ransomware more effective, increasing the risk of successful phishing, impersonation, and credential theft across affected organizations. In a global survey published July 22, 2026, 65% of ransomware-hit organizations said AI increased attack effectiveness. The finding points to a broad shift in attack success rather than a single-victim event.

Upbound Group customer data obtained without authorization

Data Leak

Updated: 23.07.2026 00:43 · First: 23.07.2026 00:43 · 📰 1 src / 1 articles · H score: 44

Upbound Group's customer information and documents were obtained without authorization, confirming a data-leak event that enabled downstream fraud in Acima. The exposed material was used to create fraudulent lease-to-own agreements, driving about $13 million in losses. Upbound said it added enhanced authentication and fraud-detection controls while investigating with external cybersecurity experts.

Upbound Group hit by ransomware attack

Incident

Updated: 23.07.2026 00:43 · First: 23.07.2026 00:43 · 📰 2 src / 2 articles · H score: 44

Upbound Group disclosed a cybersecurity incident in which attackers obtained customer information without authorization and used it to drive fraudulent Acima lease-to-own agreements, causing about $13 million in losses. The company said it responded with external cybersecurity experts, new fraud controls, and improved monitoring, and it notified federal law enforcement. No public ransomware or extortion claim had been made at disclosure time.

National Diplomatic Academy hit by cyberattack

Incident

Updated: 22.07.2026 23:06 · First: 22.07.2026 23:06 · 📰 1 src / 1 articles · H score: 28

The National Diplomatic Academy suffered a breach of its online education system that exposed personal information from MFA employees and overseas diplomats, affecting at least 6,000 people. An attacker reportedly exploited a server vulnerability in April 2025 and kept access for about 10 months before discovery in February 2026. The exposed records reportedly included IDs, names, email addresses, and encrypted passwords, prompting the ministry to block access and strengthen security.

Ubuntu snap-confine patch release (CVE-2026-8933)

Security Patch Release

Updated: 22.07.2026 13:50 · First: 22.07.2026 13:50 · 📰 2 src / 2 articles · H score: 34

Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unprivileged user obtain root access on default Ubuntu Desktop 24.04, 25.10, and 26.04 installations. Qualys Threat Research Unit disclosed the flaw on July 21 and described a race condition during sandbox initialization that can be chained to write malicious rules under /run/udev/rules.d/ and trigger systemd-udevd as root. Administrators were urged to verify the installed snapd version and apply the latest package updates immediately to reduce the risk of local root compromise on exposed desktop and endpoint systems.

Stadler Rail hit by ransomware attack

Incident

Updated: 22.07.2026 19:59 · First: 22.07.2026 19:59 · 📰 1 src / 1 articles · H score: 41

Stadler Rail disclosed a supplier-shared data exchange platform breach tied to the Everest ransomware gang, which demanded 10 million Swiss francs and about $12.3 million. The incident was identified as occurring in mid-July 2026 and was handled as a criminal extortion case. Stadler said its IT systems and production operations were not impacted, limiting the operational fallout to the stolen data and ransom threat.

TrickBot DNS tunneling C2 variant

Malware Activity

Updated: 22.07.2026 18:00 · First: 22.07.2026 18:00 · 📰 1 src / 1 articles · H score: 22

The TrickBot malware family has switched its C2 from HTTP to a bespoke DNS tunneling channel, hiding beacons and payloads in malformed queries. The redesign routes encrypted traffic through a public resolver and preserves the family’s modular execution model. On July 22, 2026, the change raised detection risk while showing the malware remains actively maintained.

Adobe security patch release for CVE-2026-48294

Security Patch Release

Updated: 22.07.2026 16:22 · First: 22.07.2026 16:22 · 📰 2 src / 2 articles · H score: 31

Adobe fixed CVE-2026-48294 in the Acrobat Chrome extension, closing a flaw that could expose WhatsApp Web data for users on vulnerable versions. The 26.5.2.3 release was delivered automatically, and users are being told to verify they are on the latest build.

Adobe Acrobat extension Chrome HermeticReader security flaw (CVE-2026-48294)

Vulnerability

Updated: 22.07.2026 16:22 · First: 22.07.2026 16:22 · 📰 1 src / 1 articles · H score: 24

The Adobe Acrobat extension for Chrome flaw CVE-2026-48294 let attacker-controlled pages reach WhatsApp Web conversations and rendered data without authentication. The issue affected versions 26.5.2.1 and below and could expose loaded chat content from the browser tab. Adobe fixed the flaw in 26.5.2.3, and users were told to update to the latest release.

Windmill actively exploited path traversal (CVE-2026-29059)

Vulnerability

Updated: 22.07.2026 15:36 · First: 22.07.2026 15:36 · 📰 1 src / 1 articles · H score: 32

CVE-2026-29059 is an actively exploited unauthenticated path-traversal flaw in Windmill's get_log_file endpoint that can expose arbitrary server files. Attackers can use `../` sequences to read data such as /etc/passwd and, on systems with SUPERADMIN_SECRET configured, potentially recover a token that enables superadmin access and arbitrary code execution. Windmill 1.603.3 fixed the issue by sanitizing the filename parameter. Exposure data shows about 170 vulnerable systems across 24 countries, keeping the risk broad for unpatched deployments.

Langflow unauthenticated RCE flaw (CVE-2026-0770)

Vulnerability

Updated: 22.07.2026 14:43 · First: 22.07.2026 14:43 · 📰 1 src / 1 articles · H score: 49

CVE-2026-0770 in Langflow is an actively exploited vulnerability that lets unauthenticated attackers gain remote code execution as root. CISA ordered U.S. agencies to prioritize patching it, and exploitation had already been seen in the wild before the KEV listing. The flaw creates immediate risk for exposed Langflow deployments because attack activity includes credential harvesting and malware delivery attempts.

CISA orders FCEB patching under BOD 26-04

Public Sector Action

Updated: 22.07.2026 14:43 · First: 22.07.2026 14:43 · 📰 1 src / 1 articles · H score: 36

CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04. The directive raises urgency for federal defenders because the flaw is actively exploited and can allow remote code execution as root.

SharePoint exploitation wave

Exploitation Wave

Updated: 22.07.2026 14:29 · First: 22.07.2026 14:29 · 📰 1 src / 1 articles · H score: 42

In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.

Ubuntu snap-confine local privilege escalation (CVE-2026-8933)

Vulnerability

Updated: 22.07.2026 13:50 · First: 22.07.2026 13:50 · 📰 1 src / 1 articles · H score: 29

CVE-2026-8933 exposes default Ubuntu Desktop 24.04, 25.10 and 26.04 installs to local root escalation through snap-confine, letting an unprivileged user gain full host control. Canonical has released snapd updates through the Ubuntu Security Team, and administrators should verify the fix is installed. A published PoC shows the flaw can be driven through a race condition during sandbox setup.

Google CodeMender becomes a fully managed enterprise AI code security agent in Google Cloud

Security Tool/Service

Updated: 22.07.2026 13:30 · First: 22.07.2026 13:30 · 📰 1 src / 1 articles · H score: 12

Google CodeMender has moved from research into a fully managed enterprise AI code security agent inside Google Cloud, expanding automated vulnerability discovery and remediation for development teams. The service now verifies exploitability with customer-managed sandbox PoC runs and delivers tested fixes for review, reducing the gap between detection and patching. It is available through the Gemini Enterprise Agent Platform and Google AI Threat Defense, making the capability available across managed cloud and developer workflows.

Oracle July 2026 Critical Patch Update

Security Patch Release

Updated: 22.07.2026 12:33 · First: 22.07.2026 12:33 · 📰 1 src / 1 articles · H score: 31

Oracle’s July 2026 Critical Patch Update delivers 1,449 security patches for 1,434 unique CVEs across 334 products. Roughly 600 fixes address issues that can be exploited remotely without authentication, and many flaws are rated critical. Organizations should install the update as soon as possible because the affected Oracle product set is broad and high-value.

Chick-fil- hit by cyberattack

Incident

Updated: 22.07.2026 09:40 · First: 22.07.2026 09:40 · 📰 2 src / 2 articles · H score: 21

The Chick-fil-A account breach exposed customer data after a credential-stuffing attack hit its website and mobile app, and the company said at least 2,182 Texans were affected. Unauthorized parties used stolen credentials between June 17 and June 19, 2026, then the company determined on July 13, 2026 that account information may have been accessed. The exposed data included names, email addresses, membership numbers, QR codes, Chick-fil-A credit amounts, and the last four digits of payment cards. Chick-fil-A logged out impacted accounts, removed payment methods, restored balances, and told users to change passwords.

Newtonsoftt.Json.Net trojanized fork rigs Digitain FG-Crash results

Malware Activity

Updated: 22.07.2026 09:00 · First: 22.07.2026 09:00 · 📰 1 src / 1 articles · H score: 4

The Newtonsoftt.Json.Net package was found delivering a trojanized fork that can rig Digitain FG-Crash results and exfiltrate them, turning a routine library install into a targeted integrity attack. The package masquerades as Newtonsoft.Json for non-targets, but its malicious path only activates when the host reaches the FG-Crash backend method. The malicious versions span 11.0.4 through 11.0.11, published between August 13 and October 10, 2025. The payload sends rigged round results to 185.126.237[.]64:5341 with X-Seq-ApiKey: theperfectheist2025.

Microsoft Azure DevOps MCP server prompt-injection security flaw

Vulnerability

Updated: 22.07.2026 07:57 · First: 22.07.2026 07:57 · 📰 1 src / 1 articles · H score: 29

Microsoft Azure DevOps MCP server has a prompt-injection flaw in the repo_get_pull_request_by_id path that lets hidden HTML comments in pull request descriptions steer an AI review agent. The weakness can expose projects, source code, secrets, and work items the attacker cannot otherwise reach because the agent operates with the reviewer's credentials. Microsoft had already applied a prompt-injection guardrail to other tool paths, but this pull-request path returned raw text without it. No CVE has been assigned and the issue remained present in source as of July 21.