Cyber Threat Brief

Carolina Clear Tech, LLC

Your daily cybersecurity briefing. Vulnerabilities, ransomware, threat actors, and patches that matter, explained for IT professionals and business leaders protecting small and mid-sized organizations. From Carolina Clear Tech.

  1. 4h ago

    2026-08-06: JetBrains TeamCity CVE-2026-63077 added to CISA KEV with federal agencies facing an August 8

    Show Notes - 2026-08-06 Stories Covered: - Today: - JetBrains TeamCity CVE-2026-63077 RCE Under Active Exploitation (https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog) - Gitea Critical File Read Vulnerability CVE-2026-59774 (https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html) - OVSwrap Linux Kernel Local Privilege Escalation CVE-2026-64531 (https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html) - Leaked n8n API Tokens Expose 321 Live Instances (https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html) - Ransom Cartel Creator Sentenced to 16 Years (https://thehackernews.com/2026/08/ransom-cartel-creator-gets-16-years-in.html) - Snowflake Hacker Pleads Guilty Over 165 Organization Breaches (https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html) - 22-Second Automated SSH Compromise Chain (https://isc.sans.edu/diary/rss/33220) - NullReceiver: Blockchain C2 Concealment via Empty Ethereum Transfers (https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html) - Paperclip AI Agent Platform Flaws Allow Host Command Execution CVE-2026-41679 (https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html) - keyv/cacheable npm Worm Propagates via AI Agent Configuration Files (https://isc.sans.edu/diary/rss/33218) - Chinese Zbtlink Routers Ship With Factory Backdoor (https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html) - macOS ClickFix Campaign Adopts Server-Side Fingerprinting (https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/) - AI Agent Security Flaws Enable Cross-Agent Attacks (https://www.darkreading.com/vulnerabilities-threats/flaws-google-apk-python-agent-to-agent-attack) - Attackers Compile Post-Exploitation Toolkit Inside Oracle Databases (https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html) - CVE-2026-63077: JetBrains TeamCity Deserialization RCE - CVE-2026-59774: Gitea Org-Mode File Read - CVE-2026-64531: OVSwrap Linux Kernel Privilege Escalation - CVE-2026-41679: Paperclip AI Agent Command Execution - CVE-2025-68613: n8n Expression Injection - Gitea CVE Cluster (https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html) - Veeam, Terraform MCP, Django Patch Critical Flaws (https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html) - Open VSX Removes 77 Malicious Evil Twin Extensions (https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html) CVEs Referenced: CVE-2025-68613, CVE-2026-20896, CVE-2026-27771, CVE-2026-41679, CVE-2026-59774, CVE-2026-60004, CVE-2026-63077, CVE-2026-64531 Indicators of Compromise: Hashes: a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 IPs: 163.7.8.79 Full brief: https://carolinacleartech.com/brief/2026-08-06/

  2. 1d ago

    2026-08-05: INC ransomware is actively exploiting the SonicWall zero-day pair with rapid deployment times

    Show Notes - 2026-08-05 Stories Covered: - Today: - SonicWall Zero-Days Exploited by INC Ransomware (CVE-2026-15409, CVE-2026-15410) (https://cyberscoop.com/inc-ransomware-sonicwall-zero-day-attacks/) - CISA KEV Additions: Langflow, N-able, Tomcat (CVE-2026-9198, CVE-2026-18556, CVE-2026-34486) (https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html) - Microsoft Defender Adds Device Isolation to Attack Disruption (https://www.microsoft.com/en-us/security/blog/2026/08/04/129-seconds-disruption-microsoft-defender-stops-ransomware-qnet/) - 45% of Malware Samples Bypass DNS Using Direct-to-IP Connections (https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/) - ChainDrop Supply Chain Attack: 400+ npm Packages Poisoned with Self-Propagating Worm (https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/) - Smoke#Screen Campaign Delivers ScreenConnect via Rotating Social Engineering Lures (https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook) - Frontier AI Autonomous Vulnerability Discovery: 14,090 OSS Vulnerabilities in Two Months (https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/) - Greatness PhaaS Adds Device Code Phishing to Bypass MFA (https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html) - QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor Since August 2025 (https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html) - Kaspersky: Cloud Platforms Enable Phishers to Bypass MFA via AitM Attacks (https://securelist.com/cloud-platforms-in-phishing/120832/) - Unitel Angola Hit by Cyberattack Hours Before IPO (https://www.darkreading.com/cyberattacks-data-breaches/angolas-largest-telco-breached-hours-before-ipo) - cPanel Critical Flaw: SQL Execution as Database Root (CVE-2026-58048) (https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html) - Thermo Fisher Genetic Analyzers (CVE-2026-17583) (https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-216-01) - Acrisure KARR BT and DR-100 Anti-Theft Systems (CVE-2026-18411) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01) CVEs Referenced: CVE-2026-15409, CVE-2026-15410, CVE-2026-17583, CVE-2026-18411, CVE-2026-18556, CVE-2026-18577, CVE-2026-34486, CVE-2026-58047, CVE-2026-58048, CVE-2026-9198 Indicators of Compromise: IPs: 207.174.0.143, 3.0.51.0, 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32 Full brief: https://carolinacleartech.com/brief/2026-08-05/

  3. 2d ago

    2026-08-04: INC Ransomware is actively exploiting patched SonicWall VPN flaws to extract credentials and MFA

    Show Notes - 2026-08-04 Stories Covered: - Today: - INC Ransomware Exploiting SonicWall SMA 1000 Zero-Days (CVE-2026-15410, CVE-2026-15409) (https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html) - N-able N-central Authentication Bypass Exploited in the Wild (CVE-2026-18577) (https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw) - Cisco Secure Firewall Management Center Actively Exploited (CVE-2026-20316) (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - River Bank Confirms Ransomware Attack, Claims Data Deleted (https://www.securityweek.com/river-bank-says-hackers-deleted-data-stolen-in-ransomware-attack/) - N-able N-central Compromise Indicators - Police National Legal Database Breach Exposes 100,000+ Records (https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html) - Malicious npm Packages Target Alibaba Tool Users (https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html) - Chinese AI Agent Weaponized for Proxyjacking Campaign (https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm) - Minnesota Water Utilities Hit by Coordinated Cyberattacks (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - Anthropic Claude Models Breached Three Organizations During Testing (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - OpenAI Models Broke Out of Sandbox, Attacked Hugging Face (https://www.schneier.com/blog/archives/2026/08/the-openai-hack-shows-the-genie-is-out-of-the-bottle.html) - Russian Hackers Exploit Microsoft OWA Flaw for Persistent Mailbox Access (CVE-2026-42897) (https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html) - Unit 42 Discloses Passkey Attack Methods Against Google Password Manager (https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/) - Device Code Phishing Up 1,500%, Vishing Doubles (https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles) - Coldcard Hardware Wallet RNG Flaw Linked to $88.6M Bitcoin Theft (https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html) - Brazilian Educational Institutions Targeted by Ransomware and Insider Threats (https://securelist.com/incidents-at-brazilian-educational-institutions/120803/) - Russian SVR Compromises Public Wi-Fi to Deploy Malware (https://www.theregister.com/security/2026/08/03/russias-svr-borks-public-wi-fis-for-digital-surveillance/5282399) - VMware vCenter/ESX Critical Vulnerabilities (CVE-2026-59309, CVE-2026-59310) (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - JetBrains TeamCity On-Premises Authentication Bypass (CVE-2026-63077) (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - Ruby on Rails Active Storage Critical Vulnerability (CVE-2026-66066) (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - Ruflo AI Agent Platform Vulnerability (CVE-2026-59726) (https://research.checkpoint.com/2026/3rd-august-threat-intelligence-report/) - Chinese Threat Actor Deploys GHOSTBLADE on iOS Using Leaked DarkSword Kit (https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html) CVEs Referenced: CVE-2026-15409, CVE-2026-15410, CVE-2026-18556, CVE-2026-18577, CVE-2026-20316, CVE-2026-42897, CVE-2026-59309, CVE-2026-59310, CVE-2026-59726, CVE-2026-63077, CVE-2026-66066 Indicators of Compromise: IPs: 173.249.252.200, 87.249.138.34, 37.19.210.32, 68.235.46.214 Full brief: https://carolinacleartech.com/brief/2026-08-04/

  4. 3d ago

    2026-08-03: N-able shipped an incomplete patch for an authentication bypass in N-central RMM that let attackers

    Show Notes - 2026-08-03 Stories Covered: - Today: - N-able N-central Authentication Bypass (CVE-2026-18577, CVE-2026-18556) (https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html) - Linux LPE CVE-2026-31431 Exploited in Under 24 Hours (https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/) - Brinks Home Data Breach (https://databreaches.net/2026/08/02/brinks-home-confirms-data-breach-following-shinyhunters-claim/) - Sumner County Schools Data Breach Forces Delayed Start (https://databreaches.net/2026/08/02/tn-sumner-county-schools-provides-limited-update-on-data-breach/) - N-able N-central Attack Infrastructure - Russian SVR Hackers Compromise Hotel WiFi Gateways Across 7 States (CaptiveCrunch Campaign) (https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/) - US Water Sector Cyberattacks Hit at Least 7 States (https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/) - NotVPN / SplitVPN "No-Logs" VPN Breach Exposes 58 Million Connection Logs (https://databreaches.net/2026/08/02/a-no-logs-vpn-that-kept-58-million-connection-logs-inside-the-notvpn-splitvpn-breach/) - Hugging Face Diffusers Code Injection (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) (https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html) - Thermo Fisher DNA Analysis Software Flaw (CVE-2026-17583) (https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html) CVEs Referenced: CVE-2026-17583, CVE-2026-18556, CVE-2026-18577, CVE-2026-31431, CVE-2026-44513, CVE-2026-44827, CVE-2026-45804 Indicators of Compromise: IPs: 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, 68.235.46.214 Full brief: https://carolinacleartech.com/brief/2026-08-03/

  5. 4d ago

    2026-08-02: A critical Ruby on Rails RCE vulnerability (CVE-2026-66066

    Show Notes - 2026-08-02 Stories Covered: - Today: - Ruby on Rails Remote Code Execution via Active Storage (CVE-2026-66066) (https://www.securityweek.com/ruby-on-rails-patches-critical-vulnerability/) - DeadLock Ransomware Claims Spanish Biopharma Firm Diater (https://databreaches.net/2026/08/01/the-double-extortion-of-a-russian-ransomware-threatens-the-medical-records-that-diater-has-kept-for-10-years/) - Atomic macOS Stealer (AMOS) - Active Campaign (https://isc.sans.edu/diary/rss/33208) - Coldcard Hardware Wallet Firmware Flaw Enables $70M Bitcoin Theft (https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html) - CareCloud Data Breach Impacts 350,000+ Individuals (https://databreaches.net/2026/08/01/carecloud-data-breach-impacts-over-350000/) - Oceanside, CA School District Systems Disrupted by Suspected Cyberattack (https://databreaches.net/2026/08/01/suspected-cyberattack-disrupts-oceanside-california-school-district-systems/) - Healthcare Phishing: Two More Facilities Disclose Breaches (https://databreaches.net/2026/08/01/mon-general-hospital-notifies-patients-of-phishing-attack-and-breach/) - Joomla Extensions Under Active Exploitation (CVSSv3 10.0) (https://www.theregister.com/offbeat/2026/08/02/meet-the-internet-radical-who-helped-microsoft-get-email-and-att-get-online/5281281) - DEF CON 2026: Franklin Project and Baochip-1x Security Key Badge (https://arstechnica.com/security/2026/08/defcons-new-badge-is-a-security-key-you-can-see-inside/) - FCC Data Breach Rules Face Sixth Circuit Rehearing (https://databreaches.net/2026/08/01/sixth-circuit-to-rehear-case-on-fcc-data-breach-rules-case/) - CVE-2026-66066 - Ruby on Rails Active Storage Arbitrary File Read (https://www.securityweek.com/ruby-on-rails-patches-critical-vulnerability/) CVEs Referenced: CVE-2026-66066 Indicators of Compromise: Domains: 78[.]138, getmacouscloud[.]com, macostruecloud[.]xyz, macspheres[.]com, render65[.]com, grove-89[.]com Hashes: b9ec3261d633c289e51c5fa8842af4350efe68446df39cb995de82e0941d0f3c, 13b868b3ea8b492e7fbab1ca04535c53d0930650185b5a082cd59c1974689cd5, 9f25ec533cb23d020e568fb771500d7776b1300f07119ad9d0876f4329ce22ab, 0a03cf18de28017c0ea591dffc380a6b41fedd2acc3a39e901e58d9188c01836 IPs: 7.2.3.2, 8.0.5.1, 8.1.3.1 Full brief: https://carolinacleartech.com/brief/2026-08-02/

  6. 5d ago

    2026-08-01: A Chinese hacker used DeepSeek through Telegram to launch autonomous attacks exploiting five CISA

    Show Notes - 2026-08-01 Stories Covered: - Today: - Chinese Hacker Commands DeepSeek AI to Launch Autonomous Attacks (https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html) - Adobe Campaign Classic CVSS 10.0 Remote Code Execution (https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html) - Midnight Blizzard (Russian SVR) Hijacks Hotel Wi-Fi Worldwide (https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html) - Lazarus Group Sharing Tools with Ransomware Operators (https://databreaches.net/2026/07/31/north-koreas-lazarus-group-sharing-tools-with-ransomware-hackers-south-korean-agencies-warn/) - Weaponizing Exposed Data: Ransomware Groups Index and Price Stolen Data (https://databreaches.net/2026/07/31/weaponizing-exposed-data/) - RedACT Report on Italian Ransomware Environment (https://databreaches.net/2026/07/31/ransomware-in-italy-redact-report-sheds-light-on-an-evolving-threat-environment/) - XCSSET macOS Malware Returns with Version 40 (https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/) - Cheap Android TV Boxes Running Ad Fraud and Proxy Operations (https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html) - Adform Advertising Script Compromised for Crypto Wallet Swapping (https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html) - HollowFrame Loader and Matryoshka Backdoor Target Law Firm (https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html) - Device Code Phishing is the Fastest-Growing Threat of 2026 (https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html) - Anthropic Claude Models Breached Three Organizations During CTF Testing (https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html) - Chinese-Speaking Hackers Target Central Asian Governments (https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html) - Chrome 149, 150, and 151 Fix 1,442 Vulnerabilities (https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html) - 84 Flaws in 4G and 5G Core Networks (https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html) - Adobe Bridge Critical RCE and Privilege Escalation Flaws (https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html) - Joomla Extensions Exploited with Perfect 10 CVSS Scores (https://www.theregister.com/foss/2026/07/31/baddies-caught-exploiting-extensions-bugs-with-perfect-10-scores-on-vulnerable-joomla-websites/5281773) - Microsoft SharePoint Zero-Day Under Active Attack (https://www.theregister.com/security/2026/07/31/microsoft-patches-failed-to-fix-on-prem-sharepoint-which-is-now-under-zero-day-attack/5281722) CVEs Referenced: CVE-2025-68613, CVE-2026-21858, CVE-2026-3055, CVE-2026-33017, CVE-2026-3545, CVE-2026-39987, CVE-2026-48374, CVE-2026-48390, CVE-2026-48391, CVE-2026-48392, CVE-2026-48393, CVE-2026-48394, CVE-2026-48395, CVE-2026-48396, CVE-2026-48448, CVE-2026-48449 Indicators of Compromise: Domains: ssentialserv[.]xyz, multitoconference[.]com., adform[.]net, 102[.]230, 196[.]184, 252[.]84., multitoconference[.]com, 162[.]76. Full brief: https://carolinacleartech.com/brief/2026-08-01/

  7. 6d ago

    2026-07-31: Russian state hackers are actively exploiting a maximum-severity Exchange Server flaw to install

    Show Notes - 2026-07-31 Stories Covered: - Today: - Max-severity Exchange Server flaw under active exploitation by Kremlin hackers (CVE-2026-42897) (https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/) - CISA urgent alert: Water sector PLCs under active attack (https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs) - Crime Stoppers International offers $22,000 bounty for INC ransomware group (https://news.risky.biz/risky-bulletin-non-profit-offers-22-000-bounty-for-inc-ransomware-group/) - HHS OCR settles ransomware investigation of OSF Healthcare (https://databreaches.net/2026/07/30/hhs-ocr-settles-ransomware-investigation-of-osf-healthcare-system-and-affiliated-covered-entities/) - Open source supply chain compromise campaigns escalate in scale (https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/) - Microsoft Copilot for Word can copy hidden prompts into new documents (https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html) - Okta acquires identity threat detection firm Permiso Security (https://cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/) - Kaspersky details Kerberoasting detection via network anomaly analysis (https://securelist.com/tr/network-anomaly-detection-in-kata/120892/) - Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803) - Azure Resource Manager Elevation of Privilege update (CVE-2026-24304) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304) - Anthropic's Claude escaped test sandbox, attacked three organizations (https://www.theregister.com/ai-and-ml/2026/07/31/anthropics-claude-escaped-test-sandbox-to-attack-three-organizations/5281562) - Microsoft announces July 2026 security updates (https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026/) - MZ Automation GmbH libiec61850 (8 CVEs) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10) - Johnson Controls OpenBlue Employee (3 CVEs) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-02) - Schneider Electric IGSS (CVE-2026-12927) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04) - o6 Automation open62541 (4 CVEs) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08) - MikroTik RouterOS API session management (CVE-2026-14227) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01) - NASA Core Flight System Health & Safety Application (CVE-2026-18064) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06) - MZ Automation lib60870 (2 CVEs) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11) - Rockwell Automation CompactLogix/ControlLogix (CVE-2026-9636) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05) - Toptech Systems RCU II+ and Multiload II+ (CVE-2026-12562) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03) - Watchfire Controller Software (CVE-2026-5846) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09) - Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07) CVEs Referenced: CVE-2026-12562, CVE-2026-12927, CVE-2026-13584, CVE-2026-14227, CVE-2026-15352, CVE-2026-18064, CVE-2026-21662, CVE-2026-24304, CVE-2026-34495, CVE-2026-34497, CVE-2026-42897, CVE-2026-56758, CVE-2026-5846, CVE-2026-61893, CVE-2026-63033, CVE-2026-63035, CVE-2026-63362, CVE-2026-63550, CVE-2026-63559, CVE-2026-65421, CVE-2026-65423, CVE-2026-66349, CVE-2026-66360, CVE-2026-66364, CVE-2026-66369, CVE-2026-66720, CVE-2026-66803, CVE-2026-9636 Full brief: https://carolinacleartech.com/b ...

  8. Jul 30

    2026-07-30: Cisco patches actively exploited FMC zero-day granting static credential access

    Show Notes - 2026-07-30 Stories Covered: - Today: - Cisco Secure Firewall Management Center Zero-Day (CVE-2026-20316) (https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html) - Coordinated Cyberattack Targets Minnesota Water Infrastructure (https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html) - GenieLocker Ransomware Targets Russian Manufacturing (https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/) - AI-Generated Extortion Schemes Emerge (https://www.recordedfuture.com/blog/ai-generated-extortion) - Astaroth Banking Trojan Adds WhatsApp Spambot (https://www.crowdstrike.com/en-us/blog/inside-astaroths-new-spambot-component/) - SSH Cryptomining Bot Performs Hardware Reconnaissance (https://isc.sans.edu/diary/rss/33198) - Russian Hackers Exploit Microsoft OWA Zero-Day for Persistent Mailbox Access (https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html) - AppSec Scanners Exploited as Supply Chain Attack Vector (https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector) - OpenAI Models Escape Containment, Compromise Multiple Services (https://www.darkreading.com/cyberattacks-data-breaches/liable-ai-agents-escape-hugging-face-breach-questions) - Ruflo AI Platform Critical Vulnerability Enables Agent Poisoning (https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html) - FCC Blocks Foreign Robots and Power Inverters Over Cyber Risks (https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html) - Flying Eagle Mobile Malware-as-a-Service Targets Chinese Finance Apps (https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china) - Nine-Year Fraud Campaign Clones Russian Company Sites (https://thehackernews.com/2026/07/nine-year-fraud-campaign.html) - Southeast Asian Cybercriminal Syndicates Cost Region $88-114 Billion (https://www.darkreading.com/threat-intelligence/se-asian-cybercriminal-syndicates-global-power) - Critical Ruby on Rails Active Storage Arbitrary File Read (https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html) - VMware Critical Flaws: Auth Bypass, Code Execution, VM Escape (https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html) - Firefox/Tor Browser JIT Flaw Enables Browser-to-Kernel Chain (https://thehackernews.com/2026/07/researchers-show-single-malicious.html) - 73% of Organizations Not Fully Ready for Major Cyberattack (https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html) - Red Team AI Agents Train Blue Team Defenders (https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense) - CISA Publishes Updated SBOM Minimum Elements (https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom) - Amazon Attributes npm Hijacks to North Korea (https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html) - Russia Charges Telegram Founder Durov With Aiding Terrorism (https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html) - Microsoft Secure Boot Bypass Existed for 13 of 14 Years (https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html) CVEs Referenced: CVE-2025-2894, CVE-2025-35027, CVE-2025-66376, CVE-2026-10702, CVE-2026-20079, CVE-2026-20316, CVE-2026-41703, CVE-2026-41709, CVE-2026-42897, CVE-2026-47876, CVE-2026-59309, CVE-2026-59310, CVE-2026-59726, CVE-2026-66066 Indicators of Compromise: Domains: 73[.]235, 100[.]68. IPs: 91.92.40.13, 0.0.0.0, 7.2.3.1, 6.1.7.10, 7.2.3.2, 8.0.5.1, 8.1.3.1 Full brief: https://carolinacleartech.com/brief/2026-07-30/

About

Your daily cybersecurity briefing. Vulnerabilities, ransomware, threat actors, and patches that matter, explained for IT professionals and business leaders protecting small and mid-sized organizations. From Carolina Clear Tech.