ICYMI: 2026-07-29
Latest Headlines
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
US, Australia Release OT Isolation Guidance for Critical Infrastructure
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
Windows 11 KB5101684 update released with 42 changes and fixes
– MTZ