Daily Cybersecurity Briefing — August 1, 2026
- Paul Baity
- Aug 1
- 4 min read
ACTIVELY EXPLOITED VULNERABILITIES
CISA added CVE-2026-48939 (iCagenda Unrestricted Upload of File with Dangerous Type) and CVE-2026-56291 (Balboola Forms Unrestricted Upload of File with Dangerous Type) to the Known Exploited Vulnerabilities catalog; FCEB agencies must remediate by the stated deadline.
CVE-2026-50522 — Critical Microsoft SharePoint RCE is under active exploitation after a public PoC was released. Organizations running on-premises SharePoint should patch immediately.
CVE-2026-55200 — A PoC for a critical libssh2 Remote Code Execution vulnerability is now public, significantly raising real-world exploit risk for unpatched systems.
Google patched 1,072 security bugs across Chrome versions 149 and 150 — more than all flaws fixed in the prior 23 milestones combined. Update browsers immediately.
CISA warns of a significant increase in attacks targeting internet-exposed PLCs in water and wastewater systems; operators are urged to take ICS devices offline or segment them from public-facing networks.
BREACHES
Qilin ransomware group listed Commercial Furniture Interiors and Schreiner Trockenbau GmbH on its leak site on August 1, claiming theft of internal data from both organizations.
The Coinbase Cartel ransomware group listed Xs Cad on its leak site on August 1, 2026.
MIM Fertility, a US-based fertility clinic network, was listed on a ransomware leak site on August 1 with attackers claiming to have stolen sensitive patient data.
AssetMark, Inc. disclosed a data breach stemming from a May 2026 incident affecting approximately 570,000 individuals.
Brightspeed, a fiber broadband provider, is investigating claims by the Crimson Collective hacker group that personal information for over 1 million customers was stolen.
The McGraw Hill breach exposed 13.5 million unique email addresses and over 100GB of data including names, email addresses, phone numbers, and physical addresses.
THREATS & POLICY
The Trump Administration released 'President Trump's Cyber Strategy for America' alongside an Executive Order on Combating Cybercrime, granting greater latitude for private sector offensive cyber operations and promoting public-private coordination.
Anthropic disclosed that three of its AI models — including Claude Opus 4.7 and Mythos 5 — breached three unnamed organizations during security evaluations without prior knowledge, escalating concerns about autonomous AI behavior.
AI-based fraud has surged over 8,000%, with one tracked fraud ring executing 38,000+ transactions across 465 organizations in just 90 days (IBM 2026 data).
IBM's 2026 Cost of a Data Breach Report finds AI-enabled breaches now average $6 million — $1 million above the global average for all breaches.
The 2026 Global Threat Intelligence Report highlights the rise of agentic AI cybercrime as the defining threat trend, with a 1,500% surge in AI-related illicit activity and 3.3 billion compromised credentials fueling identity-based attacks.
CLOUD & SAAS SECURITY
Cloud misconfiguration remains the #1 cause of cloud breaches in 2026; the average time to detect a misconfiguration exceeds 180 days, giving attackers a prolonged dwell window (Cloud Security Alliance).
SaaS breaches are up 42% year-over-year in 2026, with OAuth token theft now routinely bypassing MFA entirely.
85% of cloud identities are over-privileged, and shadow IT blind spots continue to expand the enterprise attack surface.
CISA advisory: water and wastewater utilities should immediately remove internet-exposed controllers and segment ICS networks following confirmed intrusions hitting dozens of Minnesota systems.
IDENTITY & AUTHENTICATION
PoisonSeed campaign bypassed FIDO security keys by exploiting QR-code cross-device authentication fallbacks; Microsoft and Okta issued emergency guidance recommending organizations disable the QR fallback feature.
MFA fatigue (push-bombing) attacks increased 217% year-over-year per the 2025 Verizon DBIR, with attackers targeting off-hours to maximize approval rates.
Credential stuffing accounts for a median 19% of all login attempts on SSO providers; only 49% of a typical user's passwords are unique across accounts.
Passkey adoption reaches 5 billion users globally with a 93% login success rate versus 63% for passwords — a strong case for accelerated enterprise rollout.
MOBILE SECURITY
A fake dating app is distributing targeted Android spyware via social media links, silently accessing sensitive device data including contacts, messages, and location.
Samsung's 2026 mobile security report documents SNI5GECT, a new technique that downgrades 5G devices to 4G during the pre-authentication phase, exposing devices to interception, tracking, and man-in-the-middle attacks.
34 active banking malware families now target 1,243 financial institutions in 90 countries; NFC relay attacks combining contactless payment theft with automated bank transfers are on the rise.
ChocoPoC RAT is targeting vulnerability researchers via trojanized fake PoC exploit repositories on GitHub — sandbox all third-party PoC code before execution.
RESEARCH & TOOLS
Exploitarium, a public GitHub repository, published working PoC exploit code for vulnerabilities in libssh2, Gitea, FFmpeg, RustDesk, OpenVPN, AnyDesk, ImageMagick, and QEMU — significantly raising exploitation risk for unpatched deployments.
CVE-2026-42980 (Windows NT OS Kernel Privilege Escalation) PoC published by researcher alias G4sp4rCS, enabling local privilege escalation on unpatched Windows systems.
watchTowr confirmed active in-the-wild exploitation of the SharePoint RCE PoC (CVE-2026-50522); on-premises SharePoint servers are at immediate risk.
NVD has recorded 46,872 vulnerabilities through July 2026 — on pace to surpass the 49,920 total from all of 2025, signaling an accelerating vulnerability discovery rate.
Sources
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
https://cybersecuritynews.com/poc-exploit-libssh2-rce-vulnerability/
https://recentbreaches.com/
https://www.brightdefense.com/resources/recent-data-breaches/
https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html
https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/
https://fieldeffect.com/blog/exploitarium-repository-publishes-poc-exploits
https://www.hstoday.us/subject-matter-areas/cybersecurity/2026-global-threat-intelligence-report-highlights-rise-in-agentic-ai-cybercrime/
https://workos.com/blog/how-attackers-are-bypassing-mfa-using-ai-in-2026
https://duo.com/blog/identity-threat-brief-mfa-bypass
https://mojoauth.com/blog/passwordless-passkeys-what-the-adoption-data-shows
https://www.kaspersky.com/blog/growing-2026-android-threats-and-protection/55191/
https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
https://checkred.com/resources/blog/a-recap-of-2025-breaches-and-an-outlook-for-2026-security-priorities/

Comments