📰 DAILY THREAT BRIEFING
Friday, July 31, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 31, 2026.

  1. South Korea fines telco giant KT $39 million for customer data breach
    — Bleeping Computer

    South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 mi…
  2. JetBrains warns of critical TeamCity remote code execution flaw
    — Bleeping Computer

    JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve rem…
  3. Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
    — Dark Reading

    A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critica…
  4. AI Harnesses Burst With Potential Exploit Opps
    — Dark Reading

    A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
  5. DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
    — The Hacker News

    Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users t…
  6. Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
    — Bleeping Computer

    Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Ko…
  7. Read This Before You Buy That TV Streaming Stick
    — Krebs on Security

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming f…
  8. Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
    — Dark Reading

    In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should …
  9. ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
    — The Hacker News

    A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter…
  10. Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
    — The Hacker News

    A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read an…
  11. Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
    — Unit 42

    Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read…
  12. ISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (9684 in last 30 days).
Critical: 1 · High: 5 · Medium: 14 · Low: 0. View full dashboard →

  1. CVE-2026-66720
    — CVSS 6.5 (MEDIUM)

    The GOOSE subscriber component improperly validates the UTC timestamp
    field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
    multicast messages. A specially crafted GOOSE frame containing an
    undersized ti…
  2. CVE-2026-66421
    — CVSS 9.3 (CRITICAL)

    OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into ag…
  3. CVE-2026-66420
    — CVSS 8.8 (HIGH)

    MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional earl…
  4. CVE-2026-66369
    — CVSS 6.5 (MEDIUM)

    The GOOSE parser contains an off-by-one boundary-handling flaw that can
    be triggered by a single unauthenticated Layer-2 multicast frame on the
    process bus. When specific GOOSE message fields are processed, the
    parser…
  5. CVE-2026-66364
    — CVSS 6.5 (MEDIUM)

    The GOOSE payload parser contains a boundary handling flaw that can be
    triggered by a single unauthenticated Layer 2 multicast frame on the
    process bus. When processing specific payload fields, an attacker
    controlled …
  6. CVE-2026-66360
    — CVSS 7.5 (HIGH)

    The ISO Presentation layer contains a flaw in the handling of specific
    parameters during normal mode negotiation. A missing length check in the
    processing of the encoded presentation data allows an attacker
    controlled…
  7. CVE-2026-66349
    — CVSS 6.5 (MEDIUM)

    The MMS server connection handler contains a flaw in its processing of
    BER-encoded request data. When an MMS confirmed request PDU containing
    an extended BER tag is received over an established session, the decoder
    ma…
  8. CVE-2026-65423
    — CVSS 8.8 (HIGH)

    An integer overflow in the UA_Variant arrayDimensions product
    computation in open62541 may allow a remote attacker to trigger an
    out-of-bounds write.
  9. CVE-2026-65421
    — CVSS 6.5 (MEDIUM)

    The MMS BER decoder contains a flaw in decoding fixed-width BER fields
    (boolean/integer): an attacker-supplied length value is not validated,
    causing a read past the end of a heap buffer. This leads to termination
    of …
  10. CVE-2026-63550
    — CVSS 6.5 (MEDIUM)

    The MMS BER decoder contains a boundary-handling flaw in the processing
    of certain fields within confirmed-request messages. When a crafted
    BER-encoded element is received over an established MMS session (TCP
    port 102…
  11. CVE-2026-63362
    — CVSS 5.9 (MEDIUM)

    An unsigned integer underflow in the PubSub signature verification path
    in open62541 may allow a remote attacker to cause a denial of service
    via a crafted UDP packet.
  12. CVE-2026-63035
    — CVSS 8.1 (HIGH)

    A heap use-after-free vulnerability in the TransferSubscriptions service
    in open62541 may allow an authenticated attacker to cause a denial of
    service or potentially execute arbitrary code.
  13. CVE-2026-63033
    — CVSS 6.5 (MEDIUM)

    A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
    what fits in the ASDU body causes InformationObject_ParseObjectAddress
    to read one byte past the end of the heap-allocated message buffer.
  14. CVE-2026-61893
    — CVSS 6.5 (MEDIUM)

    A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
    inflated object count causes TestCommand_getFromBuffer to read one byte
    past the end of the heap-allocated message buffer.
  15. CVE-2026-56758
    — CVSS 6.5 (MEDIUM)

    The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
    connection establishment. When parsing certain fields within the
    calling AP title, an attacker controlled length value of zero or one may
    cause …
  16. CVE-2026-10031
    — CVSS 4.2 (MEDIUM)

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in dire…
  17. CVE-2026-68563
    — CVSS 5.5 (MEDIUM)

    A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with i…
  18. CVE-2026-68562
    — CVSS 6.2 (MEDIUM)

    A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulate…
  19. CVE-2026-64816
    — CVSS 6.5 (MEDIUM)

    RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-control…
  20. CVE-2026-63559
    — CVSS 7.5 (HIGH)

    An integer overflow in the UA_Variant arrayDimensions product
    computation in open62541 may allow a remote attacker to read
    out-of-bounds heap memory, potentially disclosing sensitive information.

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 31, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com