Cybersecurity Daily  2026-07-20

Written by

in

Companion HTML report: Download HTML report (zip)

CRITICAL SECTION

None today.

CISA KEV (last 14 days)

None listed in the collector output.

RANSOMWARE VICTIMS (today)

Doommageddon: Reni Farmácias Associadas

unsafe: CCR Solutions

qilin: PP+K, Eana, Synergy Products, Don Tortaco Mexican Grill, Associated Theatrical Contractors, City Ambulance Service, Famesa

nova: meralmanisa, Dephub, Jota Joias Premium

krybit: eurohold.bg

payload: CKR Consulting Engineers

blackout: yano.tokyo, www.miatech.net, bluebellgroup.com

thegentlemen: Ecopetrol

ULose: KyungRok, NRCapital, HanDok, HIZE Aero, MSICapital

The Green Blood Group: DAF SENEGAL, ECOBAT EGYPT

NEWS

  1. [9] Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs (HelpNetSecurity) — Reports indicate WordPress-related flaws and OAuth client ID spoofing that may bypass sign-in logs; review authentication logs and apply patches.
  2. [8] Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution (TheHackerNews) — A vulnerability reported in NGINX can crash worker processes and may allow remote code execution; administrators should apply vendor updates and restart affected services. CVE(s): CVE-2026-42533
  3. [7] UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware (TheHackerNews) — Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

    According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s

  4. [6] SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (TheHackerNews) — Several zero-day flaws in SonicWall SMA appliances are reported to have been exploited before disclosure; isolate affected appliances and seek vendor mitigations.
  5. SUMMARY

    Total new items: 30

    Critical count: 0

    Ransomware victims listed: 25

    Top CVEs to patch urgently: CVE-2026-42533

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Comments

    Leave a Reply

    Your email address will not be published. Required fields are marked *