📰 DAILY THREAT BRIEFING
Saturday, July 25, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 25, 2026.

  1. CISOs vs. Boards: Myth or Misunderstanding?
    — Dark Reading

    Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need m…
  2. OnTrac notifies customers of data breach after network hack
    — Bleeping Computer

    OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to …
  3. Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
    — Dark Reading

    The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be dif…
  4. Hermes AI agent used to automate attack on Thai Finance Ministry
    — Bleeping Computer

    A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breac…
  5. Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
    — Bleeping Computer

    Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.…
  6. BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
    — The Hacker News

    The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found…
  7. Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
    — The Hacker News

    Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certific…
  8. Vatican's Official Prayer App Leaks 700K+ Global Users' PII
    — Dark Reading

    A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser…
  9. ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
    — The Hacker News

    Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phis…
  10. ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  11. Russian Global Webmail Espionage
    — Unit 42

    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post…
  12. When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
    — SANS ISC

    Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party tha…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9497 in last 30 days).
Critical: 2 · High: 8 · Medium: 10 · Low: 0. View full dashboard →

  1. CVE-2026-66339
    — CVSS 6.5 (MEDIUM)

    A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destinati…
  2. CVE-2026-66338
    — CVSS 5.4 (MEDIUM)

    A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and …
  3. CVE-2026-66337
    — CVSS 6.5 (MEDIUM)

    A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit t…
  4. CVE-2026-61892
    — CVSS 8.8 (HIGH)

    Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
  5. CVE-2026-61886
    — CVSS 6.5 (MEDIUM)

    Weintek cMT3092X HMI stores user account passwords in plaintext.
  6. CVE-2026-60135
    — CVSS 6.5 (MEDIUM)

    An attacker can modify data that should be restricted to read‑only access.
  7. CVE-2026-60134
    — CVSS 8.8 (HIGH)

    Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
  8. CVE-2026-61884
    — CVSS 9.8 (CRITICAL)

    The web management interface of Tycon Systems TPDIN-Monitor-WEB2

     does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthentica…

  9. CVE-2026-55985
    — CVSS 4.3 (MEDIUM)

    The web management interface in 
    Tycon Systems TPDIN-Monitor-WEB2

    stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the admi…

  10. CVE-2025-71408
    — CVSS 7.8 (HIGH)

    NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. …
  11. CVE-2026-66041
    — CVSS 8.8 (HIGH)

    FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with…
  12. CVE-2026-66040
    — CVSS 8.8 (HIGH)

    FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image wi…
  13. CVE-2026-66039
    — CVSS 8.8 (HIGH)

    FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious byt…
  14. CVE-2026-66038
    — CVSS 6.5 (MEDIUM)

    FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream tha…
  15. CVE-2026-66037
    — CVSS 6.5 (MEDIUM)

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-b…
  16. CVE-2026-66036
    — CVSS 8.8 (HIGH)

    FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution in…
  17. CVE-2026-62835
    — CVSS 9.3 (CRITICAL)

    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
  18. CVE-2026-57531
    — CVSS 5.4 (MEDIUM)

    Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by cau…
  19. CVE-2026-57530
    — CVSS 5.4 (MEDIUM)

    Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaS…
  20. CVE-2026-54342
    — CVSS 8.1 (HIGH)

    In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For …

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 25, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com