Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Jul 24, 2026·3m

Daily DefSec Brief - Cyber Security News for July 24 2026

Show notes

1. Russian espionage group reads Western mailboxes through zero-click Zimbra flaw — CVE-2025-66376 — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
2. Clop exploits critical PTC Windchill/FlexPLM RCE for data-theft extortion — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
3. Kimi K3 AI agents found Redis zero-days and built working RCE chains — CVE-2026-25243, CVE-2026-25589 — The Hacker News — https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
4. GitHub Actions runners weaponized to attack cPanel and WHM servers — CVE-2026-41940 — The Hacker News — https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
5. Hotel Wi-Fi captive portals poisoned to steal M365 credentials from travelers — Cyber Security News — https://cybersecuritynews.com/one-compromised-wi-fi-gateway/
6. Emergency Chrome update fixes four high-severity memory flaws — CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, CVE-2026-16807 — Cyber Security News — https://cybersecuritynews.com/emergency-chrome-update/
7. Claude Cowork sandbox escape lets the AI agent read SSH keys off the host Mac — CVE-2026-46331 — The Hacker News — https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
8. Fake Claude installer via Bing ads on the real claude.ai domain pushes SectopRAT — Huntress via Help Net Security — https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/
9. Notepad++ abused to sideload LunchPoke and MATCHBOIL.V2 in UAC-0099 attacks — CERT-UA via BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/
10. NodeBB patches eight AI-found flaws exposing admin access and private chats — CVE-2026-58593 — The Hacker News — https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
11. Malicious RubyGems mine Monero and spread through SSH credentials — Unit 42 via Cyber Security News — https://cybersecuritynews.com/malicious-rubygems-developer-machines/
12. Johnson Controls C-CURE 9000 / Victor server flaws allow unauthenticated RCE — CVE-2026-21653, CVE-2026-21655, CVE-2026-34496 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01