Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 23, 2026·5m

Daily DefSec Brief - Cyber Security News for July 23 2026

Show notes

1. Check Point SmartConsole authentication bypass zero-day (active exploitation) — CVE-2026-16232, CVE-2026-50751 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/
2. Chaos ransomware msaRAT hides C2 in Chrome/Edge via WebRTC — No CVE — Cisco Talos: https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ · BleepingComputer: https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
3. Iranian-linked OT attacks expand to Siemens and Schneider Electric PLCs — No CVE — The Record: https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks · SecurityWeek: https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
4. RefluXFS Linux XFS kernel flaw gives local users persistent root on RHEL — CVE-2026-64600 — The Hacker News: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
5. Ubuntu snap-confine race condition allows local root on default desktop installs — CVE-2026-8933 · CVSS 7.8 — The Hacker News: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
6. Adobe Acrobat Chrome extension UXSS flaw exposed WhatsApp Web data — CVE-2026-48294 · CVSS 7.4 — BleepingComputer: https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/ · SecurityWeek: https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/
7. GeoServer CVE-2024-36401 XPath RCE still actively exploited — CVE-2024-36401 · EPSS 1.00 — SANS ISC: https://isc.sans.edu/diary/rss/33176
8. Sandworm_Mode npm worm targets AI coding assistants and CI pipelines — No CVE — Dark Reading: https://www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain · CyberScoop: https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/
9. Duplicati DLL planting vulnerability on non-default Windows install paths — CVE-2026-16157 — CERT/CC: https://kb.cert.org/vuls/id/847406
10. PyPI blocks file uploads to releases older than 14 days — No CVE — Help Net Security: https://www.helpnetsecurity.com/2026/07/23/pypi-secures-package-releases/
11. Microsoft passkey implementation flaws allow credential impersonation — CVE-2026-34348 — Dark Reading: https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
12. Multi-commit open source CVE fixes leave software exposed between patches — CVE-2012-0038, CVE-2022-2522, CVE-2023-4226 (cited examples) — Help Net Security: https://www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/