STORIES LAST WEEK
Anthropic says Claude models accessed three organizations during security tests
A testing configuration error gave Claude models internet access, leading them into three real organizations during evaluations. The incidents show that cyber-capable agents can cause external damage when containment and authorization controls fail. Reuters, July 30, 2026
CosmosEscape flaw exposed every Azure Cosmos DB account
Wiz found a Gremlin API escape that yielded a platform-wide key capable of enumerating, reading, and modifying any Cosmos DB account, including private instances. Microsoft removed the key and reported no exploitation beyond the research. Wiz Research, July 30, 2026
CISA warns of rising attacks on water utility PLCs
CISA reported increased targeting of internet-exposed programmable logic controllers after coordinated intrusions affected more than 30 Minnesota water systems. Utilities should remove controllers from public access, segment OT networks, and review PLC activity. CISA, July 30, 2026
Cisco FMC static credential flaw is under active exploitation
CVE-2026-20316 lets unauthenticated attackers log into Secure Firewall Management Center with a static low-privilege account, potentially chaining access into higher privileges. Cisco released fixes, provided compromise checks, and said no workaround exists. Cisco, July 29, 2026
Amazon links npm supply-chain attacks to North Korean hackers
Amazon connected several compromises of popular npm libraries to one North Korea-linked actor, establishing a previously unreported campaign relationship. The finding gives defenders a broader cluster for hunting malicious packages, infrastructure, and developer-targeting activity. AWS Security Blog, July 29, 2026
VMware patches ESXi escape and vCenter takeover flaws
Broadcom fixed three critical VMware flaws, including a VMXNET3 escape from guest to host, a vCenter authentication bypass, and network-reachable code execution. No exploitation was known, but the affected virtualization control plane warrants rapid patching. SecurityWeek, July 29, 2026
Critical TeamCity flaw exposes every on-premises version to remote code execution
CVE-2026-63077 lets unauthenticated HTTP clients abuse TeamCity’s agent polling protocol to run operating system commands. Compromised build servers could expose credentials, alter artifacts, and poison downstream pipelines. JetBrains, July 27, 2026
Laundry Bear deploys persistent implant through Outlook Web Access
The Russian state-linked group exploited an Outlook Web Access flaw and installed OWAReaper, a browser-based implant for persistent mailbox and credential theft. Targets included government, telecom, finance, hospitality, and aerospace organizations in the U.S. and Europe. The Record, July 29, 2026
Microsoft Teams vishing leads to Chaos ransomware in North America
Sophos tracked attackers impersonating IT staff in Teams, gaining remote access through Quick Assist or RemSupp, and deploying custom backdoors. At least three intrusions ended with Chaos ransomware, including one that reached encryption in under 17 hours. Sophos, July 28, 2026
Lazarus infrastructure overlaps with South Korean ransomware campaign
Researchers found Lazarus and Gunra ransomware operations using matching vulnerabilities, malware filenames, privilege tools, command servers, and an SSH fingerprint. The overlap suggests collaboration, shared infrastructure, or access brokering between state hackers and cybercriminals. The Record, July 30, 2026
Unauthenticated Ruflo endpoint lets attackers control AI agent swarms
Noma Labs found Ruflo’s MCP Bridge exposed 233 tools without authentication. One HTTP request could execute shell commands, steal model API keys, create attacker-controlled swarms, and poison persistent memory. Version 3.16.3 closes the flaw. Noma Security, July 29, 2026
CISA updates minimum elements for software bills of materials
CISA and international partners revised baseline SBOM fields after receiving more than 90 comments. The update gives software buyers and operators clearer component data for vulnerability tracking, procurement requirements, and supply-chain incident response. CISA, July 29, 2026
Nearly one in five data center systems sits near an internet attack path
Claroty’s analysis of 750,000 cyber-physical assets found 18% one network hop from internet-exposed systems. Weak segmentation around power, cooling, and building controls could convert a minor foothold into disruption of core data center operations. SecurityWeek, July 30, 2026
Interpol system speeds cross-border freezes of fraud payments
Interpol’s I-GRIP connects police in 196 countries with financial institutions to freeze fraudulent transfers quickly. Recent coordination stopped a $6.6 million business email compromise payment, showing why enterprises need immediate escalation paths after payment fraud. Dark Reading, July 31, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
