Cybersecurity News | Daily Recap [28 Jul 2026]

Cybersecurity News | Daily Recap [28 Jul 2026]

Cloud & Identity

  • SSO defenses and modern credential attacks remain a prime focus as organizations reassess identity security controls – SSO Protected
  • Cyera is set to acquire Oasis Security in a $1 billion deal as data and identity security consolidation accelerates – Cyera Deal
  • Microsoft unveiled MAI-Cyber-1-Flash, its first cybersecurity AI model, while also expanding AI-driven security offerings – AI Model, AI Offers
  • Google is proposing yet another threat-actor naming system to reduce confusion across vendor tracking – Naming System

Vulnerabilities & Exploitation

  • Apple patched 87 vulnerabilities in iOS and 155 in macOS Tahoe as part of a major security update – Apple Patches
  • Attackers are actively exploiting Fastjson, with zero-day RCE activity hitting U.S. firms and a separate unpatched flaw under attack – Fastjson Attack, Fastjson RCE
  • Arista VeloCloud Orchestrator has a critical zero-day being exploited in the wild – Arista Zero-Day, VeloCloud Patch
  • Check Point SmartConsole faced a zero-day exploited in attacks before patching – SmartConsole Zero-Day
  • A public CertiGhost proof-of-concept now allows attackers to hijack Windows domains – CertiGhost PoC
  • A patched vBulletin pre-auth code execution flaw now has a public exploit, increasing risk for unpatched forums – vBulletin Exploit
  • PTC Windchill vulnerability abuse is being linked to a ransomware campaign – Windchill Campaign
  • More than 24,000 exposed server BMCs are leaking password hashes through a decades-old flaw – BMC Flaw

Malware, Botnets & Ransomware

  • Dysphoria is spreading as an IoT DDoS botnet across 200,000 devices worldwide and adding blockchain C2 and victim relays after disruption – Dysphoria Botnet, Blockchain C2
  • A malware incident forced a health system in South Carolina and Georgia to close offices after network disruption – Health Malware
  • Coca-Cola confirmed data theft in the Fairlife ransomware attack, highlighting ongoing extortion risk – Fairlife Attack
  • ShinyHunters claimed responsibility for a data breach affecting Ernst & Young in an extortion-driven campaign – EY Breach

Data Breaches & Privacy

  • MCBS, a medical billing firm, suffered a breach affecting 1.26 million people – MCBS Breach
  • Origin Energy disclosed a breach impacting 900,000 Australians – Origin Breach
  • Apple faces a lawsuit over a fake App Store crypto wallet app that allegedly stole $1.8 million in Bitcoin – Fake Wallet
  • A rogue agent reportedly hacked a startup in a case that underscored how quickly AI agent misuse can turn into a security incident – Rogue Agent

ICS, VPNs & National Security

  • U.S. officials warned that Iranian hackers are targeting Siemens, Schneider, and Rockwell ICS devices – ICS Warning
  • A senator is pushing federal agencies to purge outdated VPNs as part of a broader modernization effort – VPN Warning
  • The UK court rejected Bahrainβ€˜s immunity claim in a spyware-related legal case – Spyware Ruling

Supply Chain & Ecosystem

  • GitHub and PyPI introduced policy changes aimed at strengthening supply chain security – Supply Chain Policies
  • NVIDIA formed a 37-member Open Secure AI Alliance and open-sourced the NOOA framework to support secure AI development – NVIDIA Alliance
  • Frenos, an OT security startup, raised $1.52 million to grow its industrial security business – Frenos Funding

Crypto & Financial Crime

  • Wrench attacks against crypto holders appear to be rising, signaling growing physical extortion risk tied to digital assets – Wrench Attacks

Cybersecurity News | Daily Recap – hendryadrian.com