Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 17, 2026·4m

Daily DefSec Brief - Cyber Security News for July 17 2026

Show notes

1. FortiSandbox OS command injection added to CISA KEV, actively exploited — CVE-2026-25089 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. New HTTP/2 flow-control stall DoS — CVE-2019-9511, CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 — CERT/CC VU#885548 — https://kb.cert.org/vuls/id/885548
3. 7-Zip heap overflow in XZ decompression patched — CVE-2026-14266 — Cyber Security News — https://cybersecuritynews.com/7-zip-vulnerability-code-execution/
4. Researchers describe "agent data injection" (ADI) against AI agents — The Hacker News — https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
Also mentioned:
- ACR Stealer harvests M365 files and browser tokens via ClickFix — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- Sandworm uses fake CAPTCHA pages to trick Ukrainian targets into pasting malicious PowerShell — The Record — https://therecord.media/ukraine-sandworm-hacks-captcha-powershell
- SGLang expert-parallel backup subsystem unpatched pickle deserialization RCE — CERT/CC — https://kb.cert.org/vuls/id/326070