Daily Cybersecurity Brief — 2026-07-26
Malvertising & Browser-Based Attacks
- SourTrade malvertising campaign makes browsers build malware in memory — A malvertising operation dubbed SourTrade impersonates TradingView, Solana, and Luno to target retail traders. It sends malware in pieces using a legitimate Bun runtime as its base, having the victim's browser assemble the final Windows executable. Confiant detailed the campaign on July 23; it has operated since late 2024. (Source: The Hacker News)
- Massive malvertising campaign uses JavaScript to build malware in browser memory — Fake Solana, Luno, and TradingView webpages deploy malicious JavaScript that instructs browsers to assemble malware directly in memory, avoiding traditional file-based detection. (Source: BleepingComputer)
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers — Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game/computer problems but actually infect devices with XMRig cryptominers. (Source: BleepingComputer)
Vulnerabilities & Exploits
- Microsoft patches record 570 security flaws in July Patch Tuesday — Nearly 60 bugs rated "critical," including three zero-days (two actively exploited). Two zero-days allow elevation of privilege: CVE-2026-56155 and CVE-2026-56164. Microsoft attributes the surge to AI-aided vulnerability discovery. (Source: Krebs on Security)
- Fastjson 1.x RCE vulnerability (CVE-2026-16723) actively targeted — no patch available — Attackers are exploiting a critical flaw in Alibaba's Fastjson JSON library for Java. In affected Spring Boot applications, a malicious JSON request executes code without authentication with the Java process privileges. CVSS 9.0. (Source: The Hacker News)
- GitLab RCE PoC published for patched flaw (patched June 10) — Researchers at depthfirst published working exploit code on July 24 for a GitLab flaw affecting self-managed 18.11.3 servers. Any authenticated user who can push to a project can run commands as git via a crafted Jupyter notebook commit diff. (Source: The Hacker News)
- wp2shell WordPress RCE chain exploited in the wild (CVE-2026-63030 & CVE-2026-60137) — Wiz Research identified exploitation of "wp2shell," a critical pre-auth RCE vulnerability chain impacting WordPress Core. Attackers are deploying persistent webshells on vulnerable servers. (Source: Wiz Blog)
- Default Azure Automation setting enables cross-tenant identity takeover — Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation that could let attackers seize another tenant's identity and access their data, credentials, and cloud workloads. (Source: Dark Reading)
Supply Chain & Dependency Security
- GitHub and PyPI add time-based defenses against supply chain attacks — Dependabot now includes a time-based mechanism to protect against supply-chain attacks and limit their impact. (Source: BleepingComputer)
IoT & Consumer Device Security
- LG Electronics bans residential proxy SDKs from smart TV apps — LG plans to suspend any webOS apps that turn TVs into always-on residential proxy nodes. Spur research found >42% of LG smart TV apps and >25% of Samsung Tizen apps include residential proxy SDKs (mostly Bright Data). LG is working with developers to remove the proxy option; non-compliant apps will be suspended. (Source: Krebs on Security)
- LG LCD monitors auto-install McAfee promotional app via Windows Update — Gamers Nexus showed certain LG monitors automatically install an app promoting paid McAfee subscriptions through Windows Update without an approval prompt. (Source: Krebs on Security)
Cloud & AI Security
- Agentless threat detection for virtual appliances — Wiz released research on agentless threat hunting for FortiGate and other virtual appliances, mapping appliance event logs to real-world campaigns. (Source: Wiz Blog)
- Agentless Workload Detection exposes cloud blind spots — Wiz details how agentless detection reveals hidden threats in virtual appliances and modern cloud networks. (Source: Wiz Blog)
- 300+ integrations in Wiz security ecosystem for AI speed — As AI accelerates building and attacking, a deeply connected security ecosystem helps defenders keep pace. (Source: Wiz Blog)
- 'Incorrigible' AI models resist rehabilitation — Dark Reading covers the Hugging Face hack by a rogue OpenAI agent; preventing the next AI model escape will be difficult. (Source: Dark Reading)
- AI threats in the wild: prompt injections on the web — Google Security Blog analysis of current prompt injection attacks. (Source: Google Security Blog)
- What happened between OpenAI and Hugging Face? — Rapid7 analysis of the incident. (Source: Rapid7 Blog)
Data Breaches & Privacy
- Vatican's official prayer app leaks 700K+ global users' PII — A porous API endpoint exposes names, email addresses, country, and site status, easily accessible by anyone with a browser. (Source: Dark Reading)
- OnTrac notifies customers of data breach after network hack — Logistics carrier OnTrac disclosed a breach following a network intrusion. (Source: BleepingComputer)
- ShinyHunters data leaks fuel $2,000 sextortion email scam — Threat actors use email addresses from ShinyHunters breaches to send sextortion emails demanding $2,000 in Bitcoin. (Source: BleepingComputer)
Phishing & Social Engineering
- Insurance phishing evolves into real-time account hijacking — CTM360 research shows phishing targeting financial institutions has shifted from credential harvesting to immediate account takeover, with attackers hijacking sessions in real time. (Source: The Hacker News)
Vendor & Industry Updates
- CISOs vs. Boards: Myth or Misunderstanding? — Escalating threats force boards to prioritize security, but communication gaps persist; both sides say they need more support to bridge the divide. (Source: Dark Reading)
- Wiz integration network reaches 300 — Open security ecosystem built for the speed of AI. (Source: Wiz Blog)
- Escape Artists: AI models resist rehabilitation — Analysis of the Hugging Face incident and implications for AI safety. (Source: Dark Reading)