Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 30, 2026·5m

Cyber Security News for July 30 2026 - Daily DefSec Brief

Show notes

1. Cisco Secure Firewall Management Center hardcoded password added to CISA KEV — CVE-2026-20316 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Cisco Secure FMC authentication bypass — hot fixes released — CVE-2026-20079 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
3. Three critical VMware flaws: vCenter auth bypass, RCE, and ESXi VM escape — CVE-2026-59309, CVE-2026-59310, CVE-2026-47876 — The Hacker News — https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
4. Critical unauthenticated file-read in Rails Active Storage (affects TeamCity) — CVE-2026-66066 — The Hacker News — https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
5. SonicWall VPN and firewall accounts hit by credential-stuffing spree — CyberScoop — https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/
6. Long-lived Microsoft Secure Boot bypass via old signed shims — Schneier on Security — https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html
7. Chrome 151 patches 370 flaws, including seven critical — SecurityWeek — https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/
8. Firefox JIT flaw compromises browser on a single page visit, also hit Tor Browser — CVE-2026-10702, CVE-2026-43499 — The Hacker News — https://thehackernews.com/2026/07/researchers-show-single-malicious.html
9. Node.js patches 11 flaws, including two high-severity HTTP/2 memory issues — CVE-2026-56846, CVE-2026-56847 — Cyber Security News — https://cybersecuritynews.com/node-js-fixes-11-security-flaws/
10. GitLab fixes 13 flaws, including a Workhorse info-disclosure bug — CVE-2026-6267, CVE-2026-12436, CVE-2026-15975 — Cyber Security News — https://cybersecuritynews.com/gitlab-fixes-13-security-flaws/
11. Chaos ransomware deployed after two-minute Microsoft Teams vishing calls — Cyber Security News — https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/
12. Okta details Work Panel vishing platform for helpdesk account takeovers — Cyber Security News — https://cybersecuritynews.com/cybercrime-platform-turns-helpdesk-calls/
13. Amazon ties debug/chalk and axios npm hijacks to North Korea's Sapphire Sleet — The Hacker News — https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
14. Copilot for Word prompt-injection worm self-replicates across documents — Simon Willison — https://simonwillison.net/2026/Jul/29/ai-worming-through-word/
15. Linux cryptomining campaign weaponizes PAM to hide XMRig activity — Cyber Security News — https://cybersecuritynews.com/linux-cryptomining-campaign/
16. Critical RufRoot flaw in Ruflo AI orchestration allows unauth RCE — CVE-2026-59726 — The Hacker News — https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html