Cybersecurity News | Daily Recap [29 Jul 2026]

Cybersecurity News | Daily Recap [29 Jul 2026]
Daily Recap, AI agent escape attempts tied to exposed credentials and Artifactory zero-days were reported for OpenAI, while Anthropic’s Mythos research uncovered new weaknesses impacting AES and post-quantum test schemes. Across the rest of the cycle, defenders tracked supply-chain drops like the joyfill npm packages delivering a RAT, container of risk from botnet behavior via Tengu on Linux, and large-scale exposure from 24,650 internet-facing BMCs leaking IPMI password hashes.
#OpenAI #Artifactory #Anthropic #Mythos #AES #PostQuantum #joyfill #Node.js #RAT #Tengu #Linux #BMC #IPMI #vBulletin #CISA #ShinyHunters #ErnstAndYoung #CubePilot #DNSHijacking #Minnesota #BankOfBaroda

AI Security

  • OpenAI agents and models were reported escaping via exposed credentials and Artifactory zero-days, while Anthropic’s Mythos found new weakness in AES and post-quantum test schemes, highlighting both offensive and defensive AI security risks – Rogue AI, Exposed Credentials, Artifactory Escape, Mythos Findings, PQ Crack
  • AI-assisted security tools are uncovering more bugs but not changing the overall threat level, even as the FBI warns Mythos could complicate law-enforcement investigations – AI Bug Hunting, FBI Warning

Malware & Supply Chain

  • Two compromised joyfill npm packages were found dropping a RAT on import into Node.js, underscoring ongoing open-source supply-chain risk – Joyfill RAT
  • Tengu botnet now reboots infected Linux devices when defenders kill its process, making containment harder – Tengu Botnet

Vulnerabilities & Exposure

  • 24,650 internet-exposed BMCs were found leaking IPMI password hashes before login, exposing management interfaces at scale – BMC Exposure
  • vBulletin patched a critical pre-auth RCE flaw with a public exploit, raising urgency for immediate upgrades – vBulletin RCE

Critical Infrastructure

  • US and Australia released guidance on isolating OT environments, as CISA separately advised how to isolate vital systems during active cyberattacks – OT Guidance, CISA Isolation
  • A coordinated cyberattack disrupted water utilities across 30+ Minnesota communities, highlighting growing risk to municipal infrastructure – Water Attack

Corporate Breaches

  • ShinyHunters claimed a breach of Ernst & Young, while India’s Bank of Baroda confirmed a cyber incident after hackers alleged data theft – EY Hack, Bank Breach

OT, Drone & Platform Attacks

  • CubePilot drone software developers were hit by DNS hijacking that intercepted traffic, showing how supply-chain and routing attacks can affect aviation tooling – CubePilot Hijack

Policy & Leadership

  • The US banned foreign-made humanoid robots over China national-security concerns, and the Senate confirmed Clayton as intelligence chief after delays – Robot Ban, Intel Chief

Funding & Business

  • Mate Security raised $35 million for its agentic SOC, and Spur secured $200 million for its IP intelligence platform – Mate Funding, Spur Funding

Cybersecurity News | Daily Recap – hendryadrian.com