HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 28, 2026.
-
Hackers target US firms in FastJson RCE zero-day attacks
— Bleeping Computer
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user intera… -
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
— Bleeping Computer
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being active… -
New Dysphoria DDoS botnet spreads to 200k devices worldwide
— Bleeping Computer
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS)… -
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
— Dark Reading
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access co… -
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
— Dark Reading
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of it… -
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
— The Hacker News
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for … -
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
— Dark Reading
Confidence in autonomous security tools is declining, and here's why. -
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
— The Hacker News
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-devic… -
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
— The Hacker News
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute … -
Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
— SANS ISC
Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hpr… -
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
— SANS ISC
ESAFENET's CDG showed up in our data before. The company focused on secure document management and data leakage preventio…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9393 in last 30 days).
Critical: 0 · High: 12 · Medium: 5 · Low: 0. View full dashboard →
-
CVE-2026-66473
— CVSS 7.5 (HIGH)
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. -
CVE-2026-65448
— CVSS 6.5 (MEDIUM)
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. -
CVE-2026-65447
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. -
CVE-2026-65446
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. -
CVE-2026-65445
— CVSS 6.5 (MEDIUM)
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. -
CVE-2026-65443
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. -
CVE-2026-65442
— CVSS 7.2 (HIGH)
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. -
CVE-2026-65441
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. -
CVE-2026-65440
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. -
CVE-2026-65439
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. -
CVE-2026-65438
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. -
CVE-2026-65437
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. -
CVE-2026-61957
— CVSS 7.1 (HIGH)
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions. -
CVE-2026-61953
— CVSS 7.2 (HIGH)
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. -
CVE-2026-53668
— CVSS 6.9 (MEDIUM)
React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users ⦠-
CVE-2026-53667
— CVSS 6.9 (MEDIUM)
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and o⦠-
CVE-2026-53666
— CVSS 6.1 (MEDIUM)
React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then itâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 28, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com