HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 31, 2026.
-
South Korea fines telco giant KT $39 million for customer data breach
— Bleeping Computer
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 mi… -
JetBrains warns of critical TeamCity remote code execution flaw
— Bleeping Computer
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve rem… -
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
— Dark Reading
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critica… -
AI Harnesses Burst With Potential Exploit Opps
— Dark Reading
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. -
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
— The Hacker News
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users t… -
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
— Bleeping Computer
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Ko… -
Read This Before You Buy That TV Streaming Stick
— Krebs on Security
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming f… -
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
— Dark Reading
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should … -
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
— The Hacker News
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter… -
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
— The Hacker News
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read an… -
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
— Unit 42
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read… -
ISC Stormcast For Thursday, July 30th, 2026 https://isc.sans.edu/podcastdetail/10030, (Thu, Jul 30th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (9684 in last 30 days).
Critical: 1 · High: 5 · Medium: 14 · Low: 0. View full dashboard →
-
CVE-2026-66720
— CVSS 6.5 (MEDIUM)
The GOOSE subscriber component improperly validates the UTC timestamp
field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2
multicast messages. A specially crafted GOOSE frame containing an
undersized ti⦠-
CVE-2026-66421
— CVSS 9.3 (CRITICAL)
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into ag⦠-
CVE-2026-66420
— CVSS 8.8 (HIGH)
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional earl⦠-
CVE-2026-66369
— CVSS 6.5 (MEDIUM)
The GOOSE parser contains an off-by-one boundary-handling flaw that can
be triggered by a single unauthenticated Layer-2 multicast frame on the
process bus. When specific GOOSE message fields are processed, the
parser⦠-
CVE-2026-66364
— CVSS 6.5 (MEDIUM)
The GOOSE payload parser contains a boundary handling flaw that can be
triggered by a single unauthenticated Layer 2 multicast frame on the
process bus. When processing specific payload fields, an attacker
controlled ⦠-
CVE-2026-66360
— CVSS 7.5 (HIGH)
The ISO Presentation layer contains a flaw in the handling of specific
parameters during normal mode negotiation. A missing length check in the
processing of the encoded presentation data allows an attacker
controlled⦠-
CVE-2026-66349
— CVSS 6.5 (MEDIUM)
The MMS server connection handler contains a flaw in its processing of
BER-encoded request data. When an MMS confirmed request PDU containing
an extended BER tag is received over an established session, the decoder
ma⦠-
CVE-2026-65423
— CVSS 8.8 (HIGH)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to trigger an
out-of-bounds write. -
CVE-2026-65421
— CVSS 6.5 (MEDIUM)
The MMS BER decoder contains a flaw in decoding fixed-width BER fields
(boolean/integer): an attacker-supplied length value is not validated,
causing a read past the end of a heap buffer. This leads to termination
of ⦠-
CVE-2026-63550
— CVSS 6.5 (MEDIUM)
The MMS BER decoder contains a boundary-handling flaw in the processing
of certain fields within confirmed-request messages. When a crafted
BER-encoded element is received over an established MMS session (TCP
port 102⦠-
CVE-2026-63362
— CVSS 5.9 (MEDIUM)
An unsigned integer underflow in the PubSub signature verification path
in open62541 may allow a remote attacker to cause a denial of service
via a crafted UDP packet. -
CVE-2026-63035
— CVSS 8.1 (HIGH)
A heap use-after-free vulnerability in the TransferSubscriptions service
in open62541 may allow an authenticated attacker to cause a denial of
service or potentially execute arbitrary code. -
CVE-2026-63033
— CVSS 6.5 (MEDIUM)
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer. -
CVE-2026-61893
— CVSS 6.5 (MEDIUM)
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an
inflated object count causes TestCommand_getFromBuffer to read one byte
past the end of the heap-allocated message buffer. -
CVE-2026-56758
— CVSS 6.5 (MEDIUM)
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS
connection establishment. When parsing certain fields within the
calling AP title, an attacker controlled length value of zero or one may
cause ⦠-
CVE-2026-10031
— CVSS 4.2 (MEDIUM)
SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in dire⦠-
CVE-2026-68563
— CVSS 5.5 (MEDIUM)
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with i⦠-
CVE-2026-68562
— CVSS 6.2 (MEDIUM)
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulate⦠-
CVE-2026-64816
— CVSS 6.5 (MEDIUM)
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-control⦠-
CVE-2026-63559
— CVSS 7.5 (HIGH)
An integer overflow in the UA_Variant arrayDimensions product
computation in open62541 may allow a remote attacker to read
out-of-bounds heap memory, potentially disclosing sensitive information.
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 31, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com