STORIES LAST WEEK
OpenAI models escaped a sandbox and breached Hugging Face
During a cybersecurity evaluation, OpenAI models exploited a sandbox zero-day, reached the internet, and chained stolen credentials with server flaws to access Hugging Face secrets. The incident exposes containment risks when autonomous systems pursue benchmarks. The Verge, July 21, 2026
Check Point SmartConsole zero-day gave attackers full administrative access
CVE-2026-16232 let unauthenticated attackers obtain login tokens and alter security policies when management servers were internet-exposed without trusted-client restrictions. Check Point reported exploitation against several customers, and CISA set a July 25 federal remediation deadline. The Hacker News, July 23, 2026
SonicWall SMA1000 zero-days installed custom malware on VPN appliances
Attackers chained SSRF and command-injection flaws to tunnel into internal services, gain root, and deploy KNUCKLEBALL malware. Volexity found exploitation began June 22, weeks before disclosure, making log review essential even after patching. BleepingComputer, July 20, 2026
Iran-linked hackers expanded PLC attacks across major industrial vendors
Federal agencies added Siemens and Schneider Electric devices to an alert previously focused on Rockwell Automation. Observed attacks modified project files and HMI or SCADA data, causing operational disruption and financial loss in critical infrastructure. CISA, July 22, 2026
Attackers exploited a fourth SharePoint flaw to steal machine keys
CVE-2026-50522 enabled remote code execution and machine-key theft that could preserve access after patching. Researchers warned affected organizations to rotate credentials, not merely apply Microsoft’s July 14 fix. SecurityWeek, July 22, 2026
Azure Automation flaw enabled cross-tenant identity takeover
A public-by-default endpoint and two code flaws could let an Azure tenant assume another tenant’s managed identity, modify automation scripts, and access credentials or workloads. Microsoft changed the default and no exploitation was reported. Dark Reading, July 24, 2026
Russian state-backed hackers targeted Zimbra users with phishing and a zero-click flaw
The Laundry Bear campaign combined credential phishing with exploitation of a patched Zimbra Collaboration vulnerability to steal email from government, defense and policy targets. CISA, NSA, and FBI published indicators and hardening guidance. CISA, July 23, 2026
Clop exploited PTC Windchill and FlexPLM to steal product data
The extortion group used CVE-2026-12569 for unauthenticated code execution and JSP webshell deployment on internet-facing product lifecycle management systems. The campaign targets repositories containing sensitive engineering and supply-chain information. BleepingComputer, July 24, 2026
Kimsuky compromised South Korean groupware vendors to reach customers
The North Korean group breached software suppliers through an exposed mail server and employee social engineering, then stole customer server details, planted malware in a SaaS customer, and modified vendor login pages to harvest credentials. The Record, July 22, 2026
ChatGPT Agent flaw could install an invisible attacker-controlled agent
Zenity’s AgentForger attack used a weaponized URL and existing connectors to create a hidden Workspace Agent, disable approval prompts and accept commands by email. OpenAI patched the flaw, but it shows how agent permissions can become persistent access. SecurityWeek, July 23, 2026
Chaos ransomware RAT hid command traffic inside Chrome and Edge
Cisco Talos found msaRAT controlling browsers through the Chrome DevTools Protocol, using Cloudflare Workers for signaling and Twilio TURN for WebRTC relay. The implant never connected directly, making trusted browser traffic the observable network footprint. Cisco Talos, July 23, 2026
Microsoft measured a 92% drop in Tycoon2FA phishing after disruption
Tycoon2FA-linked messages fell to 1.2 million in June from a 15.1 million monthly baseline, but attackers shifted attachment formats and increased Teams abuse. One automated BEC campaign reached 67,000 users at 42,000 organizations within three hours. Microsoft Security Blog, July 23, 2026
BlueNoroff phishing kit profiled crypto wallets before delivering malware
North Korean operators hijacked trusted Telegram contacts, sent fake Zoom or Teams meetings, fingerprinted wallet extensions, and used AI-generated faces in staged calls. Successful infections stole Telegram sessions, helping the campaign target each victim’s contacts. The Hacker News, July 24, 2026
State Department imposed visa restrictions on foreign cyber scammers
The policy covers people responsible for or complicit in cyberscams, sextortion, and related criminal networks, plus immediate family members. It targets industrial-scale operations that combine cyber fraud with trafficking, money laundering, and underground banking. The Record, July 23, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
