HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 29, 2026.
-
ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
— Dark Reading
Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who has released an open source too… -
CubePilot drone software dev hit by DNS hijacking to intercept traffic
— Bleeping Computer
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS h… -
Thousands of Data Center Controllers Open to Takeover
— Dark Reading
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have t… -
OpenAI models used Artifactory zero-days to escape to the internet
— Bleeping Computer
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated test… -
When AI Agents Escape Sandboxes, Old Security Rules Apply
— Dark Reading
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log e… -
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
— The Hacker News
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an … -
CISA shares advice on isolating vital systems during cyberattacks
— Bleeping Computer
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital oper… -
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
— The Hacker News
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its m… -
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
— The Hacker News
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces e… -
AutoIT Payload Injector , (Tue, Jul 28th)
— SANS ISC
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and po… -
ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9609 in last 30 days).
Critical: 3 · High: 8 · Medium: 9 · Low: 0. View full dashboard →
-
CVE-2026-17166
— CVSS 4.3 (MEDIUM)
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to⦠-
CVE-2026-17162
— CVSS 6.4 (MEDIUM)
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' Block Attribute in all versions up to, and including, 4.4.24 due to in⦠-
CVE-2026-17161
— CVSS 6.4 (MEDIUM)
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText' Block Attribute in all versions up to, and including, 4.4.24 due to⦠-
CVE-2026-15735
— CVSS 6.4 (MEDIUM)
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and ou⦠-
CVE-2026-12939
— CVSS 6.4 (MEDIUM)
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletters_post_thumbnail) shortcodes in versions up to and including 4.15. This⦠-
CVE-2026-12938
— CVSS 6.4 (MEDIUM)
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode in versions up to and including 4.15. This is due to insufficient inpu⦠-
CVE-2026-12144
— CVSS 8.8 (HIGH)
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field(⦠-
CVE-2026-56822
— CVSS 7.4 (HIGH)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous ⦠-
CVE-2026-56821
— CVSS 7.4 (HIGH)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing i⦠-
CVE-2026-66064
— CVSS 5.3 (MEDIUM)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from r⦠-
CVE-2026-66063
— CVSS 6.5 (MEDIUM)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenti⦠-
CVE-2026-64863
— CVSS 9.1 (CRITICAL)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce –no-delete, allowing WebD⦠-
CVE-2026-62325
— CVSS 9.1 (CRITICAL)
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'adm⦠-
CVE-2026-59921
— CVSS 5.7 (MEDIUM)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-suppl⦠-
CVE-2026-54719
— CVSS 7.5 (HIGH)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAu⦠-
CVE-2026-54658
— CVSS 9.8 (CRITICAL)
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing atta⦠-
CVE-2026-54650
— CVSS 8.6 (HIGH)
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.Escape⦠-
CVE-2026-54638
— CVSS 7.5 (HIGH)
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and ⦠-
CVE-2026-47219
— CVSS 7.5 (HIGH)
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it ⦠-
CVE-2026-55415
— CVSS 7.5 (HIGH)
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-gâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 29, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com