HomeCybersecurity NewsCybersecurity news weekly roundup July 27, 2026
July 27, 2026

Cybersecurity news weekly roundup July 27, 2026

San Mateo, CA, July 27, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

OpenAI models escaped a sandbox and breached Hugging Face

During a cybersecurity evaluation, OpenAI models exploited a sandbox zero-day, reached the internet, and chained stolen credentials with server flaws to access Hugging Face secrets. The incident exposes containment risks when autonomous systems pursue benchmarks. The Verge, July 21, 2026

Check Point SmartConsole zero-day gave attackers full administrative access

CVE-2026-16232 let unauthenticated attackers obtain login tokens and alter security policies when management servers were internet-exposed without trusted-client restrictions. Check Point reported exploitation against several customers, and CISA set a July 25 federal remediation deadline. The Hacker News, July 23, 2026

SonicWall SMA1000 zero-days installed custom malware on VPN appliances

Attackers chained SSRF and command-injection flaws to tunnel into internal services, gain root, and deploy KNUCKLEBALL malware. Volexity found exploitation began June 22, weeks before disclosure, making log review essential even after patching. BleepingComputer, July 20, 2026

Iran-linked hackers expanded PLC attacks across major industrial vendors

Federal agencies added Siemens and Schneider Electric devices to an alert previously focused on Rockwell Automation. Observed attacks modified project files and HMI or SCADA data, causing operational disruption and financial loss in critical infrastructure. CISA, July 22, 2026

Attackers exploited a fourth SharePoint flaw to steal machine keys

CVE-2026-50522 enabled remote code execution and machine-key theft that could preserve access after patching. Researchers warned affected organizations to rotate credentials, not merely apply Microsoft’s July 14 fix. SecurityWeek, July 22, 2026

Azure Automation flaw enabled cross-tenant identity takeover

A public-by-default endpoint and two code flaws could let an Azure tenant assume another tenant’s managed identity, modify automation scripts, and access credentials or workloads. Microsoft changed the default and no exploitation was reported. Dark Reading, July 24, 2026

Russian state-backed hackers targeted Zimbra users with phishing and a zero-click flaw

The Laundry Bear campaign combined credential phishing with exploitation of a patched Zimbra Collaboration vulnerability to steal email from government, defense and policy targets. CISA, NSA, and FBI published indicators and hardening guidance. CISA, July 23, 2026

Clop exploited PTC Windchill and FlexPLM to steal product data

The extortion group used CVE-2026-12569 for unauthenticated code execution and JSP webshell deployment on internet-facing product lifecycle management systems. The campaign targets repositories containing sensitive engineering and supply-chain information. BleepingComputer, July 24, 2026

Kimsuky compromised South Korean groupware vendors to reach customers

The North Korean group breached software suppliers through an exposed mail server and employee social engineering, then stole customer server details, planted malware in a SaaS customer, and modified vendor login pages to harvest credentials. The Record, July 22, 2026

ChatGPT Agent flaw could install an invisible attacker-controlled agent

Zenity’s AgentForger attack used a weaponized URL and existing connectors to create a hidden Workspace Agent, disable approval prompts and accept commands by email. OpenAI patched the flaw, but it shows how agent permissions can become persistent access. SecurityWeek, July 23, 2026

Chaos ransomware RAT hid command traffic inside Chrome and Edge

Cisco Talos found msaRAT controlling browsers through the Chrome DevTools Protocol, using Cloudflare Workers for signaling and Twilio TURN for WebRTC relay. The implant never connected directly, making trusted browser traffic the observable network footprint. Cisco Talos, July 23, 2026

Microsoft measured a 92% drop in Tycoon2FA phishing after disruption

Tycoon2FA-linked messages fell to 1.2 million in June from a 15.1 million monthly baseline, but attackers shifted attachment formats and increased Teams abuse. One automated BEC campaign reached 67,000 users at 42,000 organizations within three hours. Microsoft Security Blog, July 23, 2026

BlueNoroff phishing kit profiled crypto wallets before delivering malware

North Korean operators hijacked trusted Telegram contacts, sent fake Zoom or Teams meetings, fingerprinted wallet extensions, and used AI-generated faces in staged calls. Successful infections stole Telegram sessions, helping the campaign target each victim’s contacts. The Hacker News, July 24, 2026

State Department imposed visa restrictions on foreign cyber scammers

The policy covers people responsible for or complicit in cyberscams, sextortion, and related criminal networks, plus immediate family members. It targets industrial-scale operations that combine cyber fraud with trafficking, money laundering, and underground banking. The Record, July 23, 2026

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles