Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 29, 2026·5m

Cyber Security News for July 29 2026 - Daily DefSec Brief

Show notes

1. Coordinated OT attack disrupts 30+ Minnesota water utilities — SecurityWeek https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/ · StateScoop https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/
2. 24,650 exposed BMCs leak IPMI password hashes before login — CVE-2013-4786 — The Hacker News https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html · Dark Reading https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
3. Gitea critical RCE via attacker-planted Git hook — CVE-2026-60004 — The Hacker News https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
4. Critical OpenWrt DHCPv6 unauthenticated root RCE — CVE-2026-53921, CVE-2026-62947, CVE-2026-62948 — The Hacker News https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
5. WordPress plugin backdoored in supply-chain compromise — CVE-2026-18072 — Cyber Security News https://cybersecuritynews.com/wordpress-plugin-backdoor/
6. Two compromised @joyfill npm packages run a RAT at import time — The Hacker News https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
7. Malicious npm packages target Alibaba developers with a cross-platform RAT — Cyber Security News https://cybersecuritynews.com/npm-packages-cross-platform-rat/
8. AT&T Arris BGW210-700 unauthenticated LAN-side auth bypass — CVE-2026-16771 — CERT/CC https://kb.cert.org/vuls/id/141367
9. MikroTik RouterOS lacks brute-force protection on API auth — CVE-2026-16347 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
10. Siemens Desigo CC OpenSSL stack overflow with RCE potential — CVE-2025-15467 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01
11. Tengu botnet uses the hardware watchdog to relaunch itself — The Hacker News https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
12. CubePilot drone-software domain hijacked via DNS, TLS certs stolen — BleepingComputer https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
13. Apple patches 187 flaws across iOS, macOS, and Safari — CVE-2026-43810, CVE-2026-28849, CVE-2026-28900, CVE-2026-28914 — SANS ISC https://isc.sans.edu/diary/rss/33196 · SecurityWeek https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/
14. Flying Eagle Android RAT source code circulating, 170 servers mapped — The Hacker News https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
15. CISA and ACSC release CI Fortify guidance on isolating vital OT — CISA https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems · Cyber Security News https://cybersecuritynews.com/cisa-and-partners-release-checklist/