Cybersecurity Intelligence Report — 30 July 2026

Written by

in

CRITICAL SECTION

  • [13] Cisco warns of FMC static credential flaw exploited in zero-day attacks (BleepingComputer) — CVE-2026-20316
    Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. […]
  • [12] Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape (TheHackerNews) — CVE-2026-59309
    Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.

    The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.

    "A malicious actor with network access to vCenter

CISA KEV SECTION

CVE Vendor/Product Score Required Action
CVE-2026-20316 Unknown 6 Apply vendor patch as soon as possible

RANSOMWARE VICTIMS (DLS Monitoring)

  • [RANSOMWARE]: [RANSOMWARE] spacebears leaked StellarRAD Systems, [RANSOMWARE] incransom leaked harwal.net, [RANSOMWARE] Black X leaked sanaa hospital, [RANSOMWARE] Black X leaked Tong Kong E & E Sdn Bhd (95907X), [RANSOMWARE] insomnia leaked Sky Solutions, [RANSOMWARE] akira leaked Northwood Country Club, [RANSOMWARE] Section9 leaked ****.com.pa, [RANSOMWARE] aurora leaked Bretford Manufacturing, [RANSOMWARE] gunra leaked Weilhotel, [RANSOMWARE] NotPetya leaked Maersk

NEWS SECTION

  • [9] Russian hackers exploit Exchange OWA zero-day for long-term mailbox access (BleepingComputer) — The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. […]
  • [8] Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass (TheHackerNews) — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

  • [8] New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands (TheHackerNews) — Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.

    Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

  • [7] Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser (TheHackerNews) — Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.

    Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.

    "No settings or additional user interaction are required," Eten Zou,

  • [6] JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack (SecurityWeek) — <p>The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.</p>
    <p>The post <a href="https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/">JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
  • [6] Tengu botnet reboots Linux devices to survive removal (HelpNetSecurity) — <p>A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures. Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks. Tengu isn&#8217;t just
  • [6] ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility (HelpNetSecurity) — <p>Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy them.  The findings expose a fundamental limitation of the reactive CSPM/CNAPP model: some cloud mi
  • [6] [CISA KEV] CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability – Cisco Secure Firewall Management Center (FMC) (CISA KEV) — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability – Cisco Secure Firewall Management Center (FMC). Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-01
  • [6] [RANSOMWARE] spacebears leaked StellarRAD Systems (ransomware.live/spacebears) — Victim: StellarRAD Systems | Group: spacebears | Website: www.stellarrad.com | Country: US | Details: Since 1981, StellarRAD Systems exists to solve the critical issues facing our clients, both large and small. We provide a broad range of services and solutions to help telecommunications providers around the world facilitate change and achieve their vision while optimizing performance and productivi
  • [5] Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory (TheHackerNews) — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

    The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

  • [5] [RANSOMWARE] incransom leaked harwal.net (ransomware.live/incransom) — Victim: harwal.net | Group: incransom | Website: harwal.net | Country: AE | Details: Harwal.net

    Harwal Group is the largest plastics recycler in the Middle East, founded in 1938, with an annual processing capacity of over 200,000 tons of plastics and metals.
    Manufacturing includes construction materials, pre-engineered building systems, industrial packaging, consumer goods, and

  • [5] [RANSOMWARE] Black X leaked sanaa hospital (ransomware.live/Black X) — Victim: sanaa hospital | Group: Black X | Country: YE | Details: [AI generated] N/A
  • [5] [RANSOMWARE] Black X leaked Tong Kong E & E Sdn Bhd (95907X) (ransomware.live/Black X) — Victim: Tong Kong E & E Sdn Bhd (95907X) | Group: Black X | Website: https://wa.me/tongkong | Country: MY | Details: It contains sensitive data, including customers and banking records.
  • [5] [RANSOMWARE] insomnia leaked Sky Solutions (ransomware.live/insomnia) — Victim: Sky Solutions | Group: insomnia | Website: www.skysolutions.com.pa | Country: PA | Details: Sky Solutions is a leading distribution company for Telecommunication products and services in Panamá. Currently serving 4 regions in Panama covering +4,000 points of sales; retail chains and supermarkets.
  • [5] [RANSOMWARE] akira leaked Northwood Country Club (ransomware.live/akira) — Victim: Northwood Country Club | Group: akira | Details: Northwood Country Club is a private club located in Meridian, Mississippi, known for its beauti
    ful facilities and convenient city location. The club offers a range of amenities including cha
    mpionship golf, clubhouse dining, swimming pool, tennis, and fitness services.

    We will upload corporate dat

  • [5] [RANSOMWARE] Section9 leaked ****.com.pa (ransomware.live/Section9) — Victim: ****.com.pa | Group: Section9 | Country: PA | Details: TRAVEL
  • [5] [RANSOMWARE] aurora leaked Bretford Manufacturing (ransomware.live/aurora) — Victim: Bretford Manufacturing | Group: aurora | Website: Bretford Manufacturing | Country: US | Details: Bretford Manufacturing, Inc. is a privately held manufacturer of charging solutions for mobile devices, founded in 1948 and headquartered in Franklin Park, Illinois. With ~60 employees and ~$10M annual revenue, it serves education, healthcare, retail, and government sectors.

    The exposed material in

  • [5] [RANSOMWARE] gunra leaked Weilhotel (ransomware.live/gunra) — Victim: Weilhotel | Group: gunra | Website: weilhotel.com | Country: MY | Details: Sector: Hotel | Revenue: US$ 5,000,000
  • [5] [RANSOMWARE] NotPetya leaked Maersk (ransomware.live/NotPetya) — Victim: Maersk | Group: NotPetya | Website: maersk.com | Country: DK | Details: A.P. Moller-Maersk, the Danish shipping and logistics conglomerate, was hit by the NotPetya wiper malware, causing major disruption to its global container shipping operations.

SUMMARY

Total new items: 54; Critical count: 2; Ransomware groups active: 0; Top CVEs to patch: CVE-2026-20316, CVE-2026-59309, CVE-2026-16232, CVE-2026-60004, CVE-2026-10702

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Companion HTML report: Download report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *