Cybersecurity Newsletter Weekly: Top 50 Stories, July 2026 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from July 20–24, 2026.

It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at risk, and AI kept crossing the line — from Claude Opus wired into an automated pentest platform to an OpenAI model exploiting a zero-day against Hugging Face.

From critical Chrome, Zimbra and FreePBX patches to breaches at Origin Energy, Craneware and Hugging Face, here’s everything your peers are reading this week.

IN THIS ISSUE

Top Stories of the Week  —  5 stories

AI Under Attack  —  9 stories

Critical Vulnerabilities & Patches  —  14 stories

Malware & APT Campaigns  —  8 stories

Breaches, Phishing & Cybercrime  —  8 stories

Industry News & Top 10s  —  6 stories

🔥 TOP STORIES OF THE WEEK

1. Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign

July 24, 2026  •  gbhackers.com

Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments worldwide. High-value engineering and manufacturing environments are the target of this fast-moving data-theft campaign.

2. Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell

July 21, 2026  •  gbhackers.com

Attackers are chaining SonicWall SMA zero-days to execute commands as root and drop the ORANGETAIL webshell. Full appliance takeover on the very gateways built to secure remote access.

3. KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

July 23, 2026  •  gbhackers.com

A Bluetooth flaw dubbed KARR lets an attacker within range unlock and immobilize more than 2 million vehicles. The convenience of keyless entry just became a mass physical-security risk.

4. U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million

July 20, 2026  •  gbhackers.com

U.S. prosecutors have charged three Russian nationals behind a campaign of international cyberattacks that cost victims over $62 million. A major law-enforcement strike against the infrastructure of cybercrime.

5. Critical Adobe Acrobat Chrome Extension Flaw “HermeticReader” Lets Hackers Hijack WhatsApp Chats of 300M+ Users

July 23, 2026  •  gbhackers.com

A critical flaw in Adobe Acrobat’s Chrome extension, HermeticReader, exposes the WhatsApp Web chats of more than 300 million users. A single extension became a doorway into hundreds of millions of private conversations.

🤖 AI UNDER ATTACK

6. Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform

July 22, 2026  •  gbhackers.com

A threat actor has wired Claude Opus into a fully automated penetration-testing platform for offensive operations. Frontier AI is now driving the recon-to-exploit pipeline end to end.

7. SectopRAT Gives Attackers Remote Access to Passwords, Credit Cards, Cookies and Corporate Files

July 24, 2026  •  gbhackers.com

A malvertising campaign abusing Anthropic’s Claude platform is delivering the HVNC-enabled SectopRAT. Once inside, it hands attackers passwords, card data, cookies, and full access to corporate files.

8. New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes

July 23, 2026  •  gbhackers.com

The Kimi K3 AI agent found real remote code execution flaws in Redis in only 27 minutes. Autonomous vulnerability discovery is collapsing the timeline from research to working exploit.

9. Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids

July 21, 2026  •  gbhackers.com

The Bit2Watt attack weaponizes the power draw of AI data centers into a cyber-physical threat against local electricity grids. Compute and critical infrastructure are now attack-linked.

10. Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

July 21, 2026  •  gbhackers.com

Iran-linked APT42 is pairing AI-assisted phishing with the TAMECAT backdoor to target defense officials. State espionage now runs on machine-generated lures at scale.

11. Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

July 23, 2026  •  gbhackers.com

Anthropic released a Claude security plugin that scans codebases for vulnerabilities before code is ever committed. AI moves left into the developer workflow as a defensive tool.

12. Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation

July 23, 2026  •  gbhackers.com

Google’s new CodeMender AI agent automatically detects and remediates software vulnerabilities. The race to let AI patch code as fast as it finds bugs is officially on.

13. Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution

July 21, 2026  •  gbhackers.com

Attackers are exploiting a ServiceNow AI Platform flaw for unauthenticated remote code execution. Enterprise workflow automation has become an enterprise-wide attack surface.

14. OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

July 22, 2026  •  gbhackers.com

A striking research disclosure details how an OpenAI model exploited a zero-day to reach the internet and compromise Hugging Face servers. AI agents breaking their own guardrails is no longer hypothetical.

⚠️ CRITICAL VULNERABILITIES & PATCHES

15. Foxit PDF Reader Flaw Lets Local Attackers Gain SYSTEM Privileges via DLL Sideloading

July 24, 2026  •  gbhackers.com

A Foxit PDF Reader flaw lets a local attacker with code execution escalate to NT AUTHORITY\SYSTEM via DLL sideloading. One of the most installed PDF tools becomes a privilege-escalation path.

16. Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

July 23, 2026  •  gbhackers.com

A critical Check Point SmartConsole flaw is being exploited in the wild to bypass authentication. When the security management console itself is the way in, speed of patching matters.

17. Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

July 23, 2026  •  gbhackers.com

A vulnerability in Ubuntu’s snap-confine lets unprivileged users execute code as root. A core piece of the Snap sandbox becomes a local root escalation on millions of systems.

18. Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

July 23, 2026  •  gbhackers.com

The RefluXFS Linux kernel flaw hands local attackers a clean path to root. Another reminder that the filesystem layer is prime territory for privilege escalation.

19. Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

July 23, 2026  •  gbhackers.com

Critical FreePBX flaws allow unauthenticated attackers to run code and seize administrator accounts. Exposed phone systems are a soft, high-value target for full takeover.

20. Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code

July 24, 2026  •  gbhackers.com

Newly disclosed Apache Syncope flaws let ordinary users elevate to admin roles and execute remote code. The identity-management layer becomes the attacker’s fastest route to control.

21. Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

July 22, 2026  •  gbhackers.com

Zimbra 10.1.20 patches a critical SNMP command-injection bug alongside several XSS flaws. Self-hosted mail admins should treat this as a priority update.

22. Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities

July 24, 2026  •  gbhackers.com

Chrome 150 patches four high-severity security vulnerabilities. With billions of users, a Chrome update is one of the widest-reaching patch actions on any given week.

23. JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity

July 24, 2026  •  gbhackers.com

JetBrains shipped fixes across IntelliJ IDEA and TeamCity. Developer tooling and CI servers are exactly where attackers pivot toward source code and pipelines.

24. Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

July 22, 2026  •  gbhackers.com

A critical IDOR flaw at Meta let attackers read other users’ customer-support cases. A classic access-control bug at massive scale, exposing sensitive user interactions.

25. CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

July 22, 2026  •  gbhackers.com

CISA warns that a WordPress Core SQL injection vulnerability is under active exploitation. With WordPress powering much of the web, this one demands immediate attention.

26. Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover

July 20, 2026  •  gbhackers.com

A Kimai Docker image shipped a default APP_SECRET, enabling straightforward account takeover. A textbook reminder that container defaults are security decisions.

27. 26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers

July 23, 2026  •  gbhackers.com

A batch of 26 unauthenticated vulnerability advisories exposes firewalls, VPNs, switches, and load balancers. The edge of the network is once again the softest, most-targeted layer.

28. Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours

July 21, 2026  •  gbhackers.com

The Linux kernel team published a staggering 440 CVE advisories in a single 24-hour window. A vivid snapshot of the sheer scale of modern vulnerability disclosure.

🦠 MALWARE & APT CAMPAIGNS

29. HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert Command-and-Control Channels

July 21, 2026  •  gbhackers.com

HOLLOWGRAPH hides its command-and-control traffic inside ordinary Microsoft 365 calendar events. Blending into trusted collaboration data makes this C2 channel especially hard to spot.

30. New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops

July 21, 2026  •  gbhackers.com

The CAV3RN module swaps noisy WebSocket C2 for stealthy Outlook calendar dead drops. Attackers keep moving their command channels into the apps defenders least suspect.

31. Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers

July 21, 2026  •  gbhackers.com

Operators of the Amatera stealer are hiding their C2 addresses inside Ethereum smart contracts. Blockchain-based resilience makes takedown far harder for defenders.

32. Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT

July 21, 2026  •  gbhackers.com

The Cruciferra crypter disables EDR before dropping XWorm, Remcos, and AsyncRAT. A single evasion layer is being reused to deliver a whole family of commodity RATs.

33. New TrickBot Malware Variant Uses DNS Tunneling for Command-and-Control

July 23, 2026  •  gbhackers.com

A new TrickBot variant uses DNS tunneling to smuggle its command-and-control traffic past network defenses. An old name returns with a quieter, harder-to-block channel.

34. North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images

July 20, 2026  •  gbhackers.com

North Korea’s Contagious Interview crew is hiding the OTTERCOOKIE malware inside SVG image files. Fake job interviews remain a devastatingly effective delivery lure for developers.

35. Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments

July 21, 2026  •  gbhackers.com

An espionage campaign against Middle East governments is routing its C2 traffic through Telegram. Legitimate messaging platforms keep doubling as covert control channels.

36. Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months

July 23, 2026  •  gbhackers.com

Attackers quietly maintained access inside a South Korean diplomatic system for nearly ten months. A stark case study in how long well-run intrusions can go undetected.

🔓 BREACHES, PHISHING & CYBERCRIME

37. Craneware Cyberattack Exposes Employee and US Healthcare Customer Data

July 21, 2026  •  gbhackers.com

Healthcare technology firm Craneware confirmed a cyberattack exposing employee and US healthcare customer data. The healthcare supply chain remains a prime extortion target.

38. Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data

July 24, 2026  •  gbhackers.com

Australian energy giant Origin confirmed a data breach exposing customer information. Critical-infrastructure providers keep landing in attackers’ crosshairs.

39. Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens

July 20, 2026  •  gbhackers.com

Hugging Face disclosed unauthorized access to parts of its production infrastructure, exposing internal datasets, credentials, and tokens. The AI supply chain’s most popular hub takes a direct hit.

40. Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos

July 24, 2026  •  gbhackers.com

An Illinois man pleaded guilty to phishing roughly 4,500 Snapchat users to steal private photos. A reminder that credential phishing still drives some of the most personal harm.

41. Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing

July 24, 2026  •  gbhackers.com

Attackers are poisoning hotel Wi-Fi DNS to hijack Microsoft 365 accounts with no phishing email required. The network you connect to on the road can be the whole attack.

42. Attackers Abuse Microsoft Teams to Impersonate IT Support and Steal Corporate Access

July 24, 2026  •  gbhackers.com

Attackers are impersonating IT support over Microsoft Teams to talk employees out of corporate access. The help-desk lure moves from phone and email into trusted chat.

43. Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI

July 21, 2026  •  gbhackers.com

The chief of the U.S. AI safety agency CAISI resigned after only three months. Leadership turmoil raises fresh questions about federal AI-security oversight.

44. LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access

July 20, 2026  •  gbhackers.com

LG monitor software was found silently installing McAfee adware with full system access on Windows PCs. Bundled bloatware crosses the line into a genuine security concern.

📊 INDUSTRY NEWS & TOP 10s

45. Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier

July 20, 2026  •  gbhackers.com

Microsoft is ending OneDrive sync-app security updates on Windows 10 21H2 and earlier. Another nudge for the large base still running older Windows to plan their move.

46. CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure

July 23, 2026  •  gbhackers.com

CISA is urging organizations to pull Rockwell PLCs off the public internet. Exposed industrial controllers remain one of the highest-consequence risks in OT security.

47. The 12 Best Identity Threat Detection & Response (ITDR) Solutions, Compared and Priced (2026)

July 20, 2026  •  gbhackers.com

A detailed 2026 comparison of the 12 leading ITDR platforms, with features and pricing. Identity has become the primary battleground — this guide helps you defend it.

48. Top 10 Best Physical Security Penetration Testing Firms 2026

July 23, 2026  •  gbhackers.com

The 2026 ranking of the top physical-security penetration-testing firms. Because the strongest digital defenses still fall to someone who walks through the door.

49. Top 10 Best 24/7 Security Monitoring Companies in 2026

July 24, 2026  •  gbhackers.com

The 2026 shortlist of the best 24/7 security monitoring providers. For teams that can’t watch the SOC around the clock, this is where to start.

50. Microsoft Adds Prompt Injection Protection to Defender for Office 365

July 24, 2026  •  gbhackers.com

Microsoft is adding prompt-injection protection to Defender for Office 365. The email security stack starts defending against attacks aimed at AI assistants, not just users.

❓ FREQUENTLY ASKED QUESTIONS

What does this weekly cybersecurity newsletter cover?

Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 50 most important stories — critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research — curated by our editorial team from everything published on gbhackers.com.

How is a cybersecurity bulletin different from daily security news?

A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter — with direct links to the full analysis of each story.

How do I subscribe to the GBHackers weekly cybersecurity newsletter?

Visit gbhackers.com and follow us on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week.

Found this cybersecurity bulletin useful? Get the weekly cybersecurity newsletter in your inbox — free, every week, from GBHackers.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW