HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 30, 2026.
-
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
— Dark Reading
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accou… -
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
— Bleeping Computer
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerabil… -
Anthropic confirms Claude is down worldwide
— Bleeping Computer
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to f… -
Cisco warns of FMC static credential flaw exploited in zero-day attacks
— Bleeping Computer
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, wa… -
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
— Dark Reading
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others. -
Red Agents vs. Blue Agents: How to Make AI Better At Defense
— Dark Reading
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterp… -
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
— The Hacker News
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files f… -
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
— The Hacker News
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Cod… -
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
— The Hacker News
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of w… -
Apple Patches Everything (July 2026), (Wed, Jul 29th)
— SANS ISC
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual… -
ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
AutoIT Payload Injector , (Tue, Jul 28th)
— SANS ISC
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and po…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9651 in last 30 days).
Critical: 0 · High: 3 · Medium: 17 · Low: 0. View full dashboard →
-
CVE-2026-64685
— CVSS 5.3 (MEDIUM)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could r⦠-
CVE-2026-62946
— CVSS 5.1 (MEDIUM)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an int⦠-
CVE-2026-62363
— CVSS 5.0 (MEDIUM)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This iss⦠-
CVE-2026-62343
— CVSS 4.7 (MEDIUM)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write ⦠-
CVE-2026-67595
— CVSS 8.1 (HIGH)
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code ⦠-
CVE-2026-15157
— CVSS 4.2 (MEDIUM)
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8⦠-
CVE-2026-14643
— CVSS 5.9 (MEDIUM)
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9⦠-
CVE-2026-67439
— CVSS 4.3 (MEDIUM)
OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry o⦠-
CVE-2026-67438
— CVSS 6.6 (MEDIUM)
OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument t⦠-
CVE-2026-67437
— CVSS 7.5 (HIGH)
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registe⦠-
CVE-2026-65975
— CVSS 6.5 (MEDIUM)
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via⦠-
CVE-2026-54249
— CVSS 6.8 (MEDIUM)
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as⦠-
CVE-2026-46678
— CVSS 6.8 (MEDIUM)
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private⦠-
CVE-2026-16728
— CVSS 4.8 (MEDIUM)
undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 u⦠-
CVE-2026-13309
— CVSS 6.8 (MEDIUM)
Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel ⦠-
CVE-2026-13308
— CVSS 8.1 (HIGH)
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Eli⦠-
CVE-2026-13307
— CVSS 6.8 (MEDIUM)
Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel M⦠-
CVE-2026-13306
— CVSS 4.3 (MEDIUM)
Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV cha⦠-
CVE-2026-13305
— CVSS 6.4 (MEDIUM)
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on⦠-
CVE-2026-6336
— CVSS 5.3 (MEDIUM)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view projâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 30, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com