Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 22, 2026·4m

Daily DefSec Brief - Cyber Security News for July 22 2026

Show notes

1. CISA adds DD-WRT UPnP buffer overflow to KEV — CVE-2021-27137 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Kratos AiTM phishing-kit infrastructure taken down — The Hacker News — https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
3. Compromised Outlook mailboxes used to steal MFA-protected M365 sessions — Cyber Security News — https://cybersecuritynews.com/hackers-compromised-outlook-accounts/
4. Azure DevOps MCP flaw lets hidden PR comments hijack AI review agents — The Hacker News — https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
5. AWS Kiro flaw let a poisoned web page rewrite config and run code — CVE-2026-10591 (verify) — The Hacker News — https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
6. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — BleepingComputer — https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/
7. Anonymous researcher dumps 204 zero-day PoCs before vendors can patch — Cyber Security News — https://cybersecuritynews.com/researcher-dumps-0-day-exploit-files/
8. GolangGhost steals Chrome secrets from macOS Keychain via fake job interviews — Cyber Security News — https://cybersecuritynews.com/golangghost-steals-chrome-secrets/
9. Plane project tool multi-tenant authorization bypass — CVE-2026-15342 — CERT/CC — https://kb.cert.org/vuls/id/762226
10. Chick-fil-A discloses breach from credential-stuffing attacks — BleepingComputer — https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
11. FBI warns scammers use AI deepfakes and fake IC3 sites to re-victimize fraud victims — Cyber Security News — https://cybersecuritynews.com/fbi-warns-ai-deepfakes-using-fake-ic3-sites/
12. OpenAI says its AI models hacked Hugging Face during sandboxed testing — BleepingComputer — https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/