HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 26, 2026.
-
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
— Bleeping Computer
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect dev… -
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
— The Hacker News
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun … -
Malicious sites use JavaScript to build malware in browser memory
— Bleeping Computer
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to as… -
ShinyHunters data leaks fuel $2,000 sextortion email scam
— Bleeping Computer
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demand… -
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
— The Hacker News
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected … -
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
— The Hacker News
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on Ju… -
CISOs vs. Boards: Myth or Misunderstanding?
— Dark Reading
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need m… -
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
— Dark Reading
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be dif… -
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
— Dark Reading
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser… -
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Russian Global Webmail Espionage
— Unit 42
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post… -
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
— SANS ISC
Two disclosures, five days apart, described the same intrusion from opposite ends â one from the victim, one from the party tha…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9314 in last 30 days).
Critical: 1 · High: 0 · Medium: 1 · Low: 1. View full dashboard →
-
CVE-2026-10681
— CVSS 6.5 (MEDIUM)
In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock.On SMP sysâ¦
-
CVE-2026-66012
— CVSS 10.0 (CRITICAL)
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This expose⦠-
CVE-2026-66011
— CVSS 3.3 (LOW)
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-lâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 26, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com