Daily Cybersecurity Briefing — July 23, 2026
- Paul Baity
- Jul 23
- 3 min read
ACTIVELY EXPLOITED VULNERABILITIES
CISA added two vulnerabilities to the KEV catalog on July 22: CVE-2026-16232 (Check Point SmartConsole improper authentication, exploited against customers with certain configurations) and CVE-2026-50522 (Microsoft SharePoint deserialization of untrusted data, CVSS 9.8). Source: CISA, The Hacker News.
CVE-2026-50522, a critical SharePoint RCE patched in July's Patch Tuesday, is under active exploitation following release of a public PoC; attackers are stealing machine keys for persistence. FCEB agencies must remediate by July 25. Source: The Hacker News.
CISA's July 21 KEV additions: CVE-2021-27137 (DD-WRT stack-based buffer overflow), CVE-2026-0770 (Langflow inclusion of functionality from untrusted control sphere), CVE-2026-63030 (WordPress Core interpretation conflict), and CVE-2026-60137 (WordPress Core SQL injection). Source: CISA.
CVE-2026-6875: a critical ServiceNow AI Platform flaw is being exploited for unauthenticated code execution via a pre-auth sandbox escape. Source: The Hacker News.
F5 patched CVE-2026-42533, a critical NGINX regex map heap overflow that can crash workers and may allow RCE in specific configurations; fixed in nginx 1.30.4 (stable) and 1.31.3 (mainline). Source: The Hacker News.
CVE-2026-14266: a high-severity heap overflow in 7-Zip's XZ decoder could execute code when a user opens a crafted archive; fixed in version 26.02. Source: The Hacker News.
BREACHES
RevolutionParts.com, an e-commerce platform for automotive dealerships, suffered a data breach exposing over 5 million records (reported July 22). Source: Bright Defense / breach trackers.
Nichirei Corporation, a Japanese food manufacturer, disclosed a ransomware incident attributed to RansomHouse (July 22). Source: breach trackers.
One Community Federal Credit Union was claimed by the DragonForce ransomware group, and Argentine regional news outlet Ahora was claimed by the Nova threat actor (both July 22). Source: breach trackers.
The Anubis ransomware group claims to have stolen 1 TB of confidential data from a Coca-Cola subsidiary; separately, Coca-Cola-owned dairy maker Fairlife temporarily halted operations this month due to a ransomware attack. Source: Cybernews, SharkStriker.
THREATS & POLICY
A Chinese state-linked hacking group has been attributed to a new campaign infecting government officials in Europe, the Middle East, and South America with modular PlugX malware. Source: The Hacker News.
CrowdStrike's Global Threat Report estimates roughly 79% of intrusions are now malware-free, relying on credential theft and DLL side-loading — AI-equipped attackers are increasingly bypassing endpoint and malware-based detection entirely. Source: Cybernews / CrowdStrike.
The FirstVPN takedown highlights law enforcement's shift from pursuing individual hackers to dismantling the infrastructure, services, and supply chains powering global cybercrime. Source: Security Boulevard.
CLOUD & SAAS SECURITY
Google DeepMind announced Gemini 3.5 Flash Cyber, a specialized AI model for discovering, validating, and patching vulnerabilities, available to governments and trusted partners via CodeMender in a limited-access pilot. Source: Cybernews.
Industry research continues to find that the vast majority of cloud security failures (~95%) stem from misconfiguration, with attackers using AI to exploit misconfigured services and move laterally faster than human teams can respond. Google Cloud's Threat Horizons H1 2026 report flags identity abuse, API failures, and ungoverned AI agents as top exposure sources. Source: SentinelOne, Google Cloud, Forcepoint.
IDENTITY & AUTHENTICATION
A newly documented phishing technique (disclosed July 22) abuses the OAuth device-code flow: victims complete a real Microsoft sign-in with valid MFA, but the resulting M365 access and refresh tokens are issued to the attacker's system. Trend Micro warns the technique turns a legitimate convenience feature into an MFA bypass. Source: Cybersecurity News.
The new Bluekit phishing-as-a-service kit bypasses MFA to steal Microsoft login credentials via adversary-in-the-middle session token theft. Source: Cybersecurity News.
MOBILE SECURITY
ZeroDayRAT, a mobile spyware platform sold via Telegram, targets Android 5–16 and iOS up to version 26 (including iPhone 17 Pro), giving operators real-time surveillance and direct financial attack capability from a browser interface. Infections start with smishing, fake apps, and shared WhatsApp/Telegram links. Source: The Hacker News, Cyberpress.
RESEARCH & TOOLS
Microsoft's July Patch Tuesday fixed a record 622 flaws, including two zero-days under active attack; hours later a researcher published a PoC for a new Windows zero-day (LegacyHive), which lets a non-admin user mount any other user's registry hive with full access. Source: The Hacker News.
0patch released free micropatches for the LegacyHive zero-day on July 20, providing protection ahead of an official Microsoft fix. Source: Cybersecurity News / 0patch.
A public PoC was released for a Windows NT OS kernel privilege escalation vulnerability. Source: Cybersecurity News.
Adobe patched 7 CVSS 10.0 flaws in ColdFusion and Campaign Classic. Source: The Hacker News.
Sources
https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog
https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
https://thehackernews.com/2026/07/adobe-patches-7-cvss-100-flaws-in.html
https://thehackernews.com/2026/02/new-zerodayrat-mobile-spyware-enables.html
https://cybersecuritynews.com/hackers-let-victims-complete-mfa/
https://cybersecuritynews.com/bluekit-paas-bypasses-mfa/
https://cybersecuritynews.com/poc-windows-nt-os-kernel/
https://www.brightdefense.com/resources/recent-data-breaches/
https://sharkstriker.com/blog/july-2026-data-breaches/
https://securityboulevard.com/2026/07/is-this-the-last-of-firstvpn-law-enforcement-targets-infrastructures-role-in-cybercrime/
https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
https://cybernews.com/

Comments