Backdoor with Hardcoded Credentials Actively Exploited in Cisco Firewalls31. July 2026CybersecurityAn account with hardcoded credentials in Cisco firewall management software is being actively exploited; a Cisco update is available. Share on:
JetBrains: Critical Remote Code Execution Vulnerability in TeamCity On-Premises31. July 2026CybersecurityAn authentication vulnerability in TeamCity On-Premises allows unauthenticated access with remote code execution capability. Share on:
NIS2 implementation deadline ends July 31 – 11,000 companies face fines31. July 2026NIS2, RegulationCompanies in critical sectors must meet NIS2 requirements by July 31, otherwise face fines of up to €500,000 per company. Share on:
Coordinated Attacks on Over 30 Water Systems in Minnesota – First Distributed Campaign Against U.S. Infrastructure31. July 2026Cybersecurity, NIS2The first distributed cyberattack on multiple U.S. water systems indicates a coordinated Iranian campaign targeting programmable logic controllers, potentially linked through shared infrastructure or a systems integrator. Share on:
AI Harnesses: Trust Gaps Between Components Create Attack Surfaces30. July 2026AI Models, CybersecurityTrust gaps between the components of AI harnesses provide attackers with new exploitation vectors. Share on:
North Korea-Linked Actors Deploy macOS Malvertising with Fake Updates30. July 2026CybersecurityNorth Korea-linked actors are using fake macOS update screens to deliver malware in the Contagious Interview campaign. Share on:
Amazon Links Debug and Chalk Attacks on NPM Ecosystem to North Korean Hackers30. July 2026AI Models, CybersecurityAccording to Amazon, North Korean hackers have exploited widely distributed npm packages as an entry point for supply chain attacks. Share on:
VMware: Three Critical Security Vulnerabilities with Auth-Bypass and VM-Escape Found30. July 2026CybersecurityBroadcom patches five security vulnerabilities in VMware products, including three critical flaws with auth-bypass and VM-escape potential. Share on:
H96 Streaming Devices Abused as Botnets for Ad Fraud30. July 2026CybersecurityChinese Zhejiang Fengwo IoT Technology Ltd exploits H96 streaming sticks as botnets to defraud advertising networks using spoofed device identities. Share on:
Claude and Security Risks: What Security Teams Need to Know30. July 2026Anthropic, CybersecuritySecurity teams must assess Claude risks factually, not act according to hype cycles. Share on:
Attackers Exploit Microsoft Teams for Vishing Attacks and Chaos Ransomware Deployment30. July 2026CybersecurityAttackers use vishing over Microsoft Teams to impersonate IT support and obtain remote access for ransomware deployment. Share on:
Sweet Security Expands Runtime Enforcement with Autonomous Blocking of AI Agents30. July 2026AI Models, CybersecuritySweet Security blocks unauthorized agent actions in real time rather than detecting them retroactively – without disrupting production systems. Share on: