Daily Cyber Digest — July 28, 2026
Tengu botnet, NightLedger backdoor, Fastjson 1.x zero-day, CISA KEV additions, and more from July 28, 2026.
Published
July 28, 2026Item Count
7 itemsTLP Protocol
TLP:clearBriefing Items
Rank #1 · malware · high · medium confidence
The Hacker NewsTengu Botnet Reboots Linux Devices at Defender Kill
Nozomi Networks Labs discovered a Mirai-derived botnet called Tengu that uses hardware watchdog timers to reboot Linux devices when the main malware process is killed. Tengu supports 25 DDoS methods, runs a SOCKS5 proxy, and targets architectures from i386 to ARM and m68k.
Tengu's multi-layered persistence and self-defense mechanisms — including watchdog abuse, immutable file flags, and false systemd services — make it harder for defenders to clean compromised IoT and Linux devices. Organizations with exposed Telnet services on IoT devices are at highest risk.
#2 · incident · high
The Hacker NewsNimbus Manticore Deploys NightLedger Backdoor Across Middle East, Africa, South Asia
Kaspersky attributed a new campaign from Iranian state-backed Nimbus Manticore deploying the NightLedger Windows backdoor and WebSocket tunnelers BridgeHead and ArcBridge. Targets span Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across government, aviation, telecom, and financial sectors.
The adversary's use of covert WebSocket tunneling to relay traffic through victim networks makes detection via traditional network monitoring difficult. NightLedger's DLL side-loading and command capabilities mirror previously hard-to-detect toolsets.
#3 · vulnerability · critical
The Hacker NewsFastjson 1.x Zero-Day RCE Exploited With No Patch Available
A remote code execution vulnerability in Fastjson 1.x (end-of-life versions) is being actively exploited across financial services, healthcare, and retail sectors. Imperva confirmed the zero-day is targeting organizations using default configurations on end-of-life 1.x versions.
With no patch available and active exploitation confirmed across multiple sectors, organizations still running Fastjson 1.x face an urgent migration imperative. The situation is reminiscent of the Log4Shell response cycle.
#4 · advisory · high
CISACISA Adds Fortinet FortiOS and Arista VeloCloud Flaws to KEV Catalog
CISA added CVE-2025-68686 (Fortinet FortiOS information disclosure) and CVE-2026-16812 (Arista VeloCloud Orchestrator OS command injection) to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. FCEB agencies must remediate by deadlines specified in BOD 26-04.
Both Fortinet FortiOS and Arista VeloCloud are widely deployed in enterprise and government networks. Active exploitation of these vulnerabilities heightens the risk of unauthorized access and network compromise for unpatched systems.
#5 · research · medium
Claims Journal / BloombergAI Tools Found Twice as Many Vulnerabilities in 2026 as 2025
Frontier AI models have doubled their vulnerability discovery rate year-over-year, with Anthropic's Mythos tool finding thousands of software flaws in early testing. NSA officials expressed concern about the acceleration in discovery and potential for malicious use.
The rapid acceleration of AI-assisted vulnerability discovery creates a dual-use challenge: defenders can find and patch flaws faster, but malicious actors can also weaponize AI-discovered vulnerabilities before patches are deployed.
#6 · vulnerability · high
The Hacker NewsAI-Assisted Exploit Developed for Linux Kernel Race Condition
A researcher used AI assistance to develop a use-after-free race condition exploit (CVE-2026-53264) in the Linux kernel's network traffic-control subsystem that can elevate local users to root privileges. The flaw was patched in the upstream kernel but not yet listed in CISA's KEV catalog.
AI-assisted exploit development lowers the barrier for creating reliable kernel exploits. Linux users should verify their distribution carries the fix rather than relying on upstream version numbers alone.
#7 · vulnerability · critical
The Hacker NewsCritical TeamCity Flaw Enables Unauthenticated OS Command Execution
A critical vulnerability in JetBrains TeamCity CI/CD server allows unauthenticated attackers to execute arbitrary OS commands. TeamCity servers exposed to the internet are at immediate risk of compromise.
TeamCity servers are high-value targets in CI/CD pipeline attacks. Unauthenticated RCE in build infrastructure can lead to supply-chain compromise, code theft, and lateral movement into production environments.
Executive snapshot
July 28, 2026 brought a dense mix of active exploits and emerging threats. A sophisticated Mirai-derived botnet called Tengu demonstrated unusual persistence capabilities including hardware watchdog abuse. Iranian state-backed Nimbus Manticore expanded its toolset with a new Windows backdoor and WebSocket tunnelers targeting organizations across Africa, the Middle East, and South Asia. A Fastjson 1.x zero-day RCE is being actively exploited with no patch available. CISA added two vulnerabilities to its KEV catalog (Fortinet FortiOS and Arista VeloCloud). AI-assisted vulnerability discovery continues to accelerate, with both defenders and threat actors leveraging frontier models for exploit development.
Notable items
This cycle’s items span three dominant themes: active exploitation of unpatched vulnerabilities (Fastjson 1.x, TeamCity, Fortinet, Arista), state-sponsored cyber espionage expansion (Nimbus Manticore in Africa and South Asia), and the growing dual-use impact of AI on vulnerability discovery and exploit development. The Tengu botnet stands out as a technical curiosity — not for scale, but for a level of self-defense sophistication rarely seen in Mirai variants. The Fastjson zero-day, with its parallels to Log4Shell, underscores the long tail of risk from end-of-life libraries still running in production environments.
Watchlist
- Fastjson 1.x exploitation: Monitor for expanded targeting and potential PoC publication. Organizations should inventory and migrate from Fastjson 1.x immediately.
- Nimbus Manticore tunneling: The BridgeHead and ArcBridge tunnelers may be deployed in additional regions. Network defenders should monitor for WebSocket traffic to unusual destinations and unauthorized outbound tunnels.
- Tengu botnet scale: Nozomi’s report is a capability assessment, not an infection census. Watch for follow-up reporting from URLhaus and other sinkhole operators on botnet growth.
- AI vulnerability discovery fallout: The doubling of AI-discovered vulnerabilities may accelerate patch cycles. Track CISA KEV additions for AI-discovered flaws entering active exploitation.
- SharePoint CVE-2026-50522: Although reported July 21, active exploitation continues. Organizations with on-premises SharePoint should verify patching and rotate machine keys.