Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 21, 2026·4m

Daily DefSec Brief - Cyber Security News for July 21 2026

Show notes

1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
3. Fake CAPTCHA lures trick users into running PowerShell — Sandworm (UAC-0145) — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself
4. Zimbra patches critical unauthenticated command injection and XSS flaws — CVE-2026-10631, CVE-2026-50054, CVE-2026-50055 — SecurityWeek — https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/
5. Gitea authorization bypass lets public tokens write to private repos and trigger Actions — CVE-2026-58443 — Cyber Security News — https://cybersecuritynews.com/gitea-vulnerability/
6. HollowGraph implant uses Microsoft 365 calendar events as its C2 channel — The Hacker News — https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
7. Telegram-bot backdoors planted in Middle Eastern government networks — Cyber Security News — https://cybersecuritynews.com/hackers-telegram-bots-secret-backdoor/
8. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — The Hacker News — https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
9. Exposed WebDAV server exposes AI-assisted malware "delivery lab" — CVE list to verify against primary report — Rapid7 — https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis
10. Sandbox escapes hit Cursor, Codex, Gemini CLI, and Antigravity — CVE-2026-48124 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
11. OpenSSL silently patches "HollowByte" pre-handshake memory-exhaustion DoS — SecurityWeek — https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/
12. Linux kernel ships 400+ CVE fixes in about 24 hours — CVE-2026-64122 and others (representative) — Cyber Security News — https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/