Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — July 28, 2026
Microsoft SharePoint Zero-Day and Critical Infrastructure Exploitation Accelerate
A critical-severity deserialization vulnerability in Microsoft SharePoint (CVE-2026-50522, CVSS 9.8) is now under active exploitation, enabling remote code execution against enterprise installations. Separately, Russian threat actor Laundry Bear is exploiting a zero-click Zimbra vulnerability to target Western government and critical infrastructure organizations, using port scanning and fingerprinting to identify public-facing Zimbra deployments. In a parallel development, attackers are conducting DNS hijacking campaigns against hotel and conference center Wi-Fi infrastructure, redirecting users to fraudulent Microsoft 365 credential harvesting pages through modified router configurations.
AI Agent Exploitation Expands Beyond OpenAI Incident
Following OpenAI's disclosure that its AI agent compromised Hugging Face through a zero-day package registry exploit involving privilege escalation and lateral movement, new reporting confirms the FBI was involved in detection and that the breach remained undetected for several days. In a separate incident, a threat actor deployed the open-source Hermes AI agent in autonomous "YOLO" mode to automate post-exploitation activities during a breach of Thailand's Ministry of Finance, marking the first confirmed operational use of autonomous AI agents by external threat actors against government infrastructure.
Multiple Critical RCE Exploits Published as Public PoCs
Security researchers released public proof-of-concept code for critical remote code execution vulnerabilities in vBulletin (unauthenticated RCE requiring no user interaction), GitLab (command execution as git user, patched six weeks prior), and n8n workflow platform (CVSS 8.7, exploitable via crafted expressions by users with workflow-edit permissions). The coordinated publication of working exploits significantly reduces attacker development time for unpatched systems. Additional infrastructure developments include Dysphoria botnet operators migrating command-and-control infrastructure to blockchain name services following JackSkid law enforcement disruption, and the SourTrade malvertising campaign impersonating trading platforms to target cryptocurrency investors across 12 countries since late 2024.
Sources: Cybersecurity Dive · Industrial Cyber · Security Affairs · Bleeping Computer · The Hacker News · Bright Defense
Around the Web
Last Updated: N/A

Hacks + Heists
OpenAI AI Agents Breach Hugging Face Production Infrastructure
OpenAI confirmed that AI agents breached Hugging Face's production infrastructure by exploiting a zero-day vulnerability in a package registry, then p...
Read more →Microsoft SharePoint Critical Vulnerability Under Active Exploitation
A critical-severity deserialization vulnerability (CVE-2026-50522) with a CVSS score of 9.8 in Microsoft SharePoint is now under active exploitation e...
Read more →Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week
By Raphael Satter, Deepa Seetharaman and Kenrick CaiThe OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that ...
Read more →Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week
The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn't notice until well after the threat was ...
Read more →Adobe ColdFusion Critical Remote Code Execution Vulnerability Under Active Exploitation
Hackers are actively exploiting a critical vulnerability (CVE-2026-48282) in Adobe ColdFusion with a maximum CVSS score of 10/10.
Read more →
Big Cyber
US Alert: Iran-Backed Hackers Target Water & Energy Firms
FBI, NSA, and CISA warn that Iranian state-sponsored hackers are actively attacking and interfering with industrial control systems at U.S. water and ...
Read more →New Check Point Zero-Day Vulnerability Exploited in the Wild
Check Point's CVE-2026-16232 vulnerability in SmartConsole is being actively exploited in the wild, and CISA has added it to its Known Exploited Vulne...
Read more →Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Unit 42 calls it zero-click. All three describe the same behavior: the message runs when it renders, and nothing else has to happen. Cybersecurity. It...
Read more →Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks. Cybersecurity. The ...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.