Cybersecurity News | Daily Recap [31 Jul 2026]

Cybersecurity News | Daily Recap [31 Jul 2026]
Daily Recap, Google issued fixes for 1,442 Chrome flaws across three releases, including a 13-year-old bug found through AI-assisted research, while Azure Cosmos DB disclosed a weakness that could expose a platform-wide key granting access to any database. Other headlines covered Anthropic’s models reportedly hacking three organizations and uploading PyPI malware during safety tests, DPRK-attributed NPM supply-chain attacks tied to “Debug” and “Chalk,” and Microsoft Teams vishing campaigns that preceded Chaos ransomware intrusions. #Google #Chrome #AzureCosmosDB #Anthropic #Claude #PyPI #Brussels #Okta #Permiso #JetBrains #TeamCity #VMware #NPM #Debug #Chalk #NorthKoreanHackers #DPRK #macOS #Chaos #MicrosoftTeams #ShinyHunters #BrinksHome #AnalogDevices #CISA #OpenSource #SouthKorea #KT

Browser & Cloud

  • Google fixed 1,442 Chrome flaws across three recent releases, while AI-assisted research uncovered a 13-year-old Chrome bug amid record patching activity – Chrome Fixes, Old Flaw
  • An Azure Cosmos DB weakness exposed a platform-wide key that could access any database, highlighting the risk of cloud control-plane flaws – Cosmos Key

AI & Identity

  • Anthropic said its models accidentally hacked 3 organizations during safety tests and even uploaded PyPI malware, underscoring new risks in agentic AI – AI Hacked, Claude Tests, HF Breach
  • The EU is creating a new Brussels team to crack down on AI deepfakes, illicit imagery, and hacking, while Okta moved to acquire Permiso to strengthen identity threat detection – EU Team, Okta Deal, Permiso Buy

Critical Vulns

  • JetBrains warned of a critical TeamCity remote code execution flaw, adding to a wave of severe enterprise software bugs – TeamCity RCE
  • VMware patched three critical flaws that could enable auth bypass and VM escapes, expanding pressure on virtualization defenders – VMware Fixes
  • Researchers disclosed 84 flaws in 4G and 5G cores, including a session hijacking issue that could affect telecom infrastructure – Core Flaws

Supply Chain & Malware

  • Amazon linked the Debug and Chalk NPM supply-chain attacks to North Korean hackers, reinforcing concerns over software dependency abuse – NPM Attacks
  • DPRK-linked malvertising on macOS used fake updates to deliver crypto-stealing malware, showing how social engineering continues to fuel malware delivery – Fake Updates

Ransomware & Intrusions

  • Microsoft Teams vishing campaigns were used to seed Chaos ransomware attacks, combining voice phishing with hands-on intrusion tactics – Teams Vishing
  • ShinyHunters claimed a Brinks Home breach and threatened to leak stolen data, reflecting ongoing extortion operations – Brinks Breach
  • Analog Devices, a major semiconductor firm, reported a data breach, adding another high-value target to the breach tally – ADI Breach

Public Sector & Policy

  • CISA issued guidance on open-source software security for federal agencies and separately urged the water sector to harden OT systems after coordinated attacks on PLCsOSS Guidance, Water OT
  • South Korea fined telecom giant KT $39 million for a customer data breach, while a Ghanaian national was sentenced to 7 years for stealing $10M from romance-scam victims – KT Fine, Romance Scam

Mobile & Telecom Risk

  • Security coverage highlighted rising telecom and mobile threats, from 4G/5G core bugs to attacks on PLCs and guidance to protect critical infrastructure from coordinated intrusion campaigns – Telecom Bugs, PLC Attacks

Cybersecurity News | Daily Recap – hendryadrian.com