Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 31, 2026·4m

Cyber Security News for July 31 2026 - Daily DefSec Brief

Show notes

1. CISA warns of active attacks locking operators out of water-sector PLCs — CISA — https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
2. Critical SolarWinds Web Help Desk SAML auth bypass — CVE-2026-28323, CVE-2026-28299 — Cyber Security News — https://cybersecuritynews.com/solarwinds-flaw-bypass-web-help-desk-saml-login/
3. SGLang LLM-serving framework — six unpatched flaws incl. unauth RCE — CVE-2026-15969, CVE-2026-14890, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 — CERT/CC — https://kb.cert.org/vuls/id/281278
4. PHP patches SQL injection and memory-corruption flaws — CVE-2026-17543, CVE-2026-17544, CVE-2026-7260 — Cyber Security News — https://cybersecuritynews.com/php-patches-three-flaws/
5. Azure Cosmos DB flaw exposed a platform-wide key across tenants — The Hacker News — https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
6. XCSSET macOS malware returns with fileless v40 — Unit 42 — https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
7. DPRK macOS malvertising uses ClickFix fake updates — The Hacker News — https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
8. State-sponsored campaign exploits Korean AnySign4PC — CVE-2020-7882 — The Hacker News — https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
9. DeepSeek-powered "Hermes" agent runs near-autonomous attacks — Cyber Security News — https://cybersecuritynews.com/deepseek-powered-hermes-agent/
10. Silver Fox uses 3-driver BYOVD chain to deliver ValleyRAT — The Hacker News — https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
11. Astaroth banking trojan spreads through WhatsApp Web sessions — Cyber Security News — https://cybersecuritynews.com/astaroth-malware-turns-your-whatsapp-account/
12. The Gentlemen ransomware kills ~180 security processes via kernel driver — Cyber Security News — https://cybersecuritynews.com/gentlemen-ransomware-kills-security-processes/
13. PipeWire flaw lets Flatpak apps escape the Linux sandbox — CVE-2026-5674, CVE-2025-60616 — Embrace The Red — https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/
14. SSH bot profiles Linux hardware before staging cryptominers — SANS ISC — https://isc.sans.edu/diary/rss/33202
15. Anthropic says Claude models escaped test environments and compromised three orgs — BleepingComputer — https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/