Jul 28, 2026
7 itemsDaily Cyber Digest — July 28, 2026
Tengu botnet, NightLedger backdoor, Fastjson 1.x zero-day, CISA KEV additions, and more from July 28, 2026.
Tag archive
All visible posts matching this normalized tag.
Jul 28, 2026
7 itemsTengu botnet, NightLedger backdoor, Fastjson 1.x zero-day, CISA KEV additions, and more from July 28, 2026.
Jul 13, 2026
5 itemsFive high-signal cyber developments from July 11-13, 2026: Joomla zero-days in CISA KEV, exposed Evilginx ops, a jscrambler npm infostealer, Pakistan police portal espionage, and unpatched AI-infra flaws.
NEWS
The jscrambler npm package was compromised; installing 8.14.0 runs a cross-platform Rust infostealer that steals cloud keys, crypto wallets, and AI-tool credentials.
Jul 11, 2026
5 itemsJuly 10, 2026 roundup: AI-driven patch pressure, a 200+ GitHub malware network, active Django SQLi, HalluSquatting, and a malicious Injective npm SDK.
NEWS
Socket tracks 'Operation Muck and Load', a 222-repo GitHub lure network that uses a fake Go module to drop RATs, infostealers, and cryptominers.
Jul 10, 2026
5 itemsJuly 9 roundup covering Defender patching, Helix SharePoint extortion, proxy malware, npm hardening, and open-source sabotage risk.
Jul 09, 2026
6 itemsJuly 8 brought exploited vulnerability updates, UniFi critical patches, Langflow credential-harvesting activity, and fresh research on ORB and AI-agent abuse.
Jul 07, 2026
6 itemsCritical remote-access auth bypasses, a 16-year Linux KVM VM-escape flaw, Cisco ISE RCE, Chrome and Teams threats lead the day.
NEWS
Fresh research shows malicious AI agent skills can evade static scanners, pushing defenders toward runtime sandboxing and stricter skill governance.
Jul 02, 2026
5 itemsSource-backed July 1 digest covering active exploitation, critical enterprise patching, AI/browser attack research, and fake-PoC supply-chain abuse.
NEWS
A June 30 report says attackers exploited SimpleHelp CVE-2026-48558 to gain RMM technician access and deliver TaskWeaver plus Djinn Stealer.
NEWS
Microsoft temporarily disabled repositories after reports of Miasma worm activity targeting developer IDE and AI coding tool workflows.
NEWS
Kaspersky and CyberPress report a SharkLoader campaign that abuses public exploits and fake installers to sideload Cobalt Strike onto government and enterprise systems.