Cybersecurity News | Daily Recap [23 Jul 2026]

Cybersecurity News | Daily Recap [23 Jul 2026]
Daily Recap, Microsoft 365 experienced a service outage impacting Teams and SharePoint, while Exchange Online also faced a mailbox quarantine issue during active repair. Multiple Linux and application risks were reported, including the RefluXFS root-privilege flaw and the Windmill authentication-bypass data exposure being exploited, alongside new threats such as msaRAT routing C2 through Chrome and Edge. #Microsoft365 #Teams #SharePoint #ExchangeOnline #RefluXFS #root #Ubuntu #snap-confine #Windmill #Chrome #Edge #msaRAT

Microsoft Issues

  • Microsoft 365 users faced an outage affecting Teams, SharePoint, and other services while Exchange Online also saw a mailbox quarantine issue under active repair – M365 Outage, Mailbox Fix

Linux & Desktop Flaws

  • A new RefluXFS Linux flaw can let local attackers gain root privileges, adding to a separate Ubuntu snap-confine bug that could also grant root on default desktop installs – RefluXFS Flaw, Ubuntu Root
  • A Windmill vulnerability is being exploited to read arbitrary server files without authentication, exposing sensitive data on vulnerable systems – Windmill Flaw
  • An Adobe Acrobat extension flaw could let malicious sites read WhatsApp Web data, widening browser-based privacy risk – Acrobat Flaw

Malware & AI Threats

  • New msaRAT malware hides its command-and-control traffic by routing through Chrome and Edge browsers, making detection harder – msaRAT
  • JadePuffer agentic attacks are now targeting AI model data with ransomware, showing how generative AI systems are becoming direct extortion targets – JadePuffer
  • Malware is also being used against AI tools in software development environments, reinforcing growing supply-chain and GenAI risk – AI Tool Attack, GenAI Risk

Enterprise Breaches & Ransomware

  • Upbound said a breach led to $13 million in fraudulent Acima leases, highlighting the financial impact of account compromise – Upbound Hack
  • Stadler, the Swiss rail giant, rejected a $12.3M ransom demand after a cyberattack, underscoring continued pressure from extortion crews – Stadler Ransom
  • Suno and Paidwork disclosed breaches affecting tens of millions of accounts, adding to a wave of large-scale exposure incidents – Mass Breaches

Government, Policy & Geopolitics

  • Check Point warned that a SmartConsole zero-day is being exploited in attacks, while federal agencies broadened an alert on Iran-linked OT activity – SmartConsole Zero-Day, Iran OT Alert
  • South Korea disclosed a data breach impacting diplomats worldwide, and the White House accused a Chinese company of distilling Anthropic’s Fable model – Korea Breach, AI Distillation
  • CISA info-sharing protections were extended in the House defense bill, while a study found most federal cyber reporting rules are duplicative – CISA Extension, Rules Study
  • France moved toward a social media ban for under-15s, reflecting rising regulatory pressure on online platforms – France Ban
  • ANCHOR-CI was proposed as a way to repair decades of broken government-industry collaboration on critical infrastructure – ANCHOR-CI

Supply Chain & Security Research

  • GitHub is cutting public bug bounty payouts and moving top rewards to a VIP tier, changing incentives for researchers – GitHub Bounty
  • Palo Alto Networks announced plans to acquire observability platform provider Embrace, signaling continued consolidation in security tooling – Palo Alto Deal
  • An InfraTrust report outlined which infrastructure flaws admins should patch first to reduce exposure more quickly – InfraTrust Report

Cybersecurity News | Daily Recap – hendryadrian.com