Daily Cyber Digest: July 7, 2026
Critical remote-access auth bypasses, a 16-year Linux KVM VM-escape flaw, Cisco ISE RCE, Chrome and Teams threats lead the day.
Published
July 07, 2026Item Count
6 itemsTLP Protocol
TLP:clearBriefing Items
Rank #1 · vulnerability · critical · high confidence
BleepingComputerBeyondTrust patches critical auth-bypass flaws in remote access software
BeyondTrust urged customers to patch two critical authentication-bypass vulnerabilities in Remote Support and Privileged Remote Access that could let attackers bypass authentication.
Remote-access and privileged-access tooling is a prime initial-access target; auth bypasses can lead directly to full compromise of managed estates.
#2 · malware · high
BleepingComputerFake Microsoft Teams IT-support calls deliver EtherRAT malware
Attackers impersonate corporate IT support over Microsoft Teams voice calls to trick employees into installing EtherRAT, gaining initial network access.
Living-off-trust social-engineering via legitimate collaboration tools bypasses perimeter controls and is hard to detect with signature tooling.
#3 · vulnerability · high
Cisco PSIRTCisco ISE Remote Code Execution and information disclosure flaws
Multiple vulnerabilities in Cisco ISE and ISE-PIC could allow a remote attacker to achieve RCE or information disclosure; no workarounds are available.
ISE sits at the core of network identity and access control; remote code execution there risks broad lateral-movement potential.
#4 · vulnerability · high
SecurityWeekLinux KVM 'Januscape' VM-escape flaw (CVE-2026-53359)
A 16-year-old KVM shadow-MMU defect (CVE-2026-53359, dubbed Januscape) can let a guest escape the VM and run code on Intel and AMD hosts; patched in mainline on June 19.
VM escape breaks tenant isolation in cloud and multi-tenant environments, threatening confidentiality and integrity of host systems.
#5 · advisory · medium
Canadian Centre for Cyber SecurityGoogle Chrome security advisory AV26-669
On July 7 Google published a Chrome advisory; the Canadian Cyber Centre urges users to update Chrome for Desktop prior to 150.0.7871.100/101.
Browser patches close routinely exploited attack surface; timely updates reduce drive-by and in-the-wild exploit risk.
#6 · tooling · medium
Trend MicroTrend Micro DPI rules: Splunk auth bypass and Crawl4AI RCE
Trend Micro released DPI rules covering Splunk Enterprise auth bypass (CVE-2026-20253) and Crawl4AI hooks code execution (CVE-2026-26216).
Network-level detection coverage for high-impact auth-bypass and AI-tooling RCE gives defenders a faster signal on exploitation attempts.
Executive snapshot
July 7, 2026 was dominated by authentication-bypass and remote-code-execution disclosures across privileged-access, network-identity, and virtualization stacks. BeyondTrust shipped fixes for two critical auth-bypass flaws in remote-access products, while Cisco remediated RCE and information-disclosure issues in ISE with no available workaround. A 16-year-old Linux KVM defect (Januscape) resurfaced as a VM-escape risk on Intel and AMD hosts. On the threat-actor side, a Microsoft Teams social-engineering campaign pushed EtherRAT for initial access. Government and vendor advisories rounded out the day with a Chrome update (AV26-669) and new Trend Micro detection rules for Splunk and Crawl4AI flaws.
Notable items
The day’s pattern is authentication and isolation failure: two of the highest-severity items (BeyondTrust, Januscape) erode the trust boundaries defenders rely on for privileged access and VM separation. Cisco ISE RCE compounds this by threatening the identity-control plane itself. The EtherRAT-over-Teams campaign shows attackers leaning on legitimate collaboration tooling and human trust rather than exploits. The Chrome and Trend Micro items are the more routine but still operationally important patch-and-detect signals that should feed standard update and detection pipelines.
Watchlist
- Prioritize BeyondTrust Remote Support/PRA and Cisco ISE patching; both are internet- and identity-adjacent and lack workarounds (Cisco).
- Hunt for Teams-based social-engineering and EtherRAT indicators; brief help desks on verifying unsolicited IT-support calls.
- Inventory Linux KVM hosts and apply kernel fixes for CVE-2026-53359; treat multi-tenant VMs as higher risk until patched.
- Roll out Chrome 150.0.7871.100+ and deploy Trend Micro DPI rules for CVE-2026-20253 and CVE-2026-26216.
- Watch for follow-on proof-of-concept or in-the-wild exploitation of the auth-bypass and VM-escape flaws.