Cybersecurity News | Daily Recap [21 Jul 2026]

Cybersecurity News | Daily Recap [21 Jul 2026]
Daily Recap, Malware reports highlighted HollowGraph’s Microsoft 365 Calendar/Graph-based C2 evasion and FakeGit’s use of 7,600 GitHub repositories to deliver SmartLoader, alongside SonicWall SMA1000 zero-days exploited for weeks before patching. On the exposure and incident front, ServiceNow exploitation appeared within days, Qilin ransomware targeted Palo Alto GlobalProtect, and multiple organizations—including Estée Lauder and Clover Health—reported breaches tied to Oracle E-Business and other issues. #HollowGraph #Microsoft365 #GraphC2 #FakeGit #SmartLoader #SonicWallSMA1000 #ServiceNow #PaloAltoGlobalProtect #Qilin #EsteeLauder #OracleEBusiness #CloverHealth

Malware & C2

  • HollowGraph malware abused Microsoft 365 Calendar/Graph events for stealthy C2 and file hiding, with reports noting 2050-dated events to mask activity – HollowGraph, HollowGraph Hidden, Graph C2
  • FakeGit abused 7,600 GitHub repositories to distribute SmartLoader malware, while a separate exposed-server report described an AI-assisted phishing toolkit tied to a WebDAV malware campaign – FakeGit, WebDAV Tooling
  • SonicWall SMA1000 zero-days were exploited for weeks to deliver custom malware before patching, highlighting active pre-patch abuse – SonicWall Zero-Days, SonicWall Weeks

Exploits & Vulnerabilities

  • ServiceNow vulnerability exploitation was observed just days after disclosure, underscoring rapid attacker response to new flaws – ServiceNow Exploit
  • Meta paid a $78,000 bug bounty for a flaw exposing customer support data, while OpenSSL quietly fixed the HollowByte DoS issue and Windows received unofficial patches for the LegacyHive zero-day – Meta Bounty, HollowByte Fix, LegacyHive Patches
  • Cursor, Codex, Gemini CLI, and Antigravity were all hit by sandbox escapes, showing ongoing isolation failures in AI tooling – AI Sandbox Escapes

Ransomware, Breaches & Theft

  • Qilin ransomware is exploiting a critical Palo Alto GlobalProtect VPN bug, while Estée Lauder disclosed a breach via an Oracle E-Business flaw and Clover Health also reported a data breach – Palo Alto Bug, Estée Breach, Clover Breach
  • Ostium lost $23.7 million in crypto in an off-chain attack, adding to this week’s high-value thefts – Ostium Theft

Government, Policy & Awards

  • The U.S. seized more than 1,000 piracy domains tied to illegal World Cup streaming, as authorities continued a major crackdown – World Cup Seizure, DOJ Action
  • SecurityWeek launched the Critical Impact Awards for industrial cybersecurity, while coverage also highlighted identity security gaps in critical infrastructure and World Cup resilience lessons – Critical Impact, Identity Gaps, World Cup Resilience
  • India said allegedly leaked Kudankulam nuclear plant files pose no safety risk, and a U.S. commerce AI standards office director exited after just three monthsIndia Nuclear, AI Standards

Funding & AI Security

  • Empirical Security raised $25 million in Series A funding, while Neo emerged from stealth with $100 million to secure enterprise AI software – Empirical Funding, Neo Funding
  • Commentary this week argued that blocking AI models will not stop the cyber threats they create, reinforcing the need for defensive controls over outright bans – AI Threats

Infrastructure & Operations

  • Microsoft issued a manual fix for WSUS sync delays and timeouts, addressing operational issues for administrators – WSUS Fix
  • Flock Safety shut down its acoustic “human distress” detection system after scrutiny over the surveillance feature – Flock Audio

Cybersecurity News | Daily Recap – hendryadrian.com