A critical vulnerability in Ruflo, an open source AI agent platform hosting swarms for Codex and Claude Code, earned a perfect CVSS score of 10. Researchers at Noma Labs found that a single unauthenticated HTTP request could grant full remote code execution — exposing API keys, stored conversations, and shell access.
What makes CVE-2026-59726 especially alarming: attackers can poison the AI's memory, planting instructions that manipulate future responses long after they've left the system. A patch alone won't fix that.
Ruflo pushed a fix within 24 hours of disclosure on June 30. Affected organizations should rotate AI provider credentials, audit platform memory for tampering, and rebuild containers from scratch.
Source: Dark Reading
A critical vulnerability in Ruflo, an open source AI agent platform hosting swarms for Codex and Claude Code, earned a perfect CVSS score of 10. Researchers at Noma Labs found that a single unauthenticated HTTP request could grant full remote code execution — exposing API keys, stored conversations, and shell access.
What makes CVE-2026-59726 especially alarming: attackers can poison the AI's memory, planting instructions that manipulate future responses long after they've left the system. A patch alone won't fix that.
Ruflo pushed a fix within 24 hours of disclosure on June 30. Affected organizations should rotate AI provider credentials, audit platform memory for tampering, and rebuild containers from scratch.
Source: Dark Reading
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 records from the UK Department for Education and the Police National Legal Database. The breach exposed names, email addresses, phone numbers, and job titles of government officials, school leaders, university staff, and police officers.
Around 600,000 records came from the DfE's help-desk portal, with a smaller batch from its Turing student exchange program. The PNLD breach added roughly 135,000 records, including stolen passwords. The gang is demanding payment from 14 alleged victims, threatening to publish all data if ignored. Authorities say the risk is currently low.
Source: The Guardian
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 records from the UK Department for Education and the Police National Legal Database. The breach exposed names, email addresses, phone numbers, and job titles of government officials, school leaders, university staff, and police officers.
Around 600,000 records came from the DfE's help-desk portal, with a smaller batch from its Turing student exchange program. The PNLD breach added roughly 135,000 records, including stolen passwords. The gang is demanding payment from 14 alleged victims, threatening to publish all data if ignored. Authorities say the risk is currently low.
Source: The Guardian
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down well and treatment plant controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems. Security experts flagged cellular communication links to remote assets like pump stations as the likely attack vector — a known blind spot in infrastructure security. Drinking water remains safe across all affected cities.
Source: SecurityWeek
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down well and treatment plant controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems. Security experts flagged cellular communication links to remote assets like pump stations as the likely attack vector — a known blind spot in infrastructure security. Drinking water remains safe across all affected cities.
Source: SecurityWeek
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.
Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.
Source: Dark Reading
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.
Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.
Source: Dark Reading
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek
CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.
Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.
Source: Cybersecurity News
CISA has added six Microsoft zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaws span Windows Shell, MSHTML, Office Word, Desktop Window Manager, Remote Access Connection Manager, and Remote Desktop Services — covering privilege escalation, security bypasses, and denial-of-service attacks.
Microsoft released patches in its February 2026 Patch Tuesday. Federal agencies must remediate by CISA's deadlines under Binding Operational Directive 22-01. Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organizations should apply patches immediately and audit exposure across Office, RDS, and remote access tools.
Source: Cybersecurity News
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator running Microsoft 365 AiTM attacks since March 2026; mail-argenta, a Nigerian operator whose own credentials appeared in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year.
All three built MFA-bypassing infrastructure from public GitHub repositories. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator running Microsoft 365 AiTM attacks since March 2026; mail-argenta, a Nigerian operator whose own credentials appeared in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year.
All three built MFA-bypassing infrastructure from public GitHub repositories. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. GitHub users pulling Go dependencies are directly at risk.
Source: SecurityWeek
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. GitHub users pulling Go dependencies are directly at risk.
Source: SecurityWeek