Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (24 July 2026)
Published: Loading…
At a Glance
- Federal agencies expanded a critical infrastructure advisory to include Iranian exploitation of Siemens, Schneider, and Rockwell PLCs.
- Check Point patched CVE-2026-16232, a critical SmartConsole authentication bypass exploited against a handful of customers.
- Qualys disclosed CVE-2026-64600, a nine-year-old XFS race condition giving local users root on default RHEL installs.
- Russian group Laundry Bear exploited a Zimbra zero-click flaw, CVE-2025-66376, to steal emails and 2FA codes for months.
- Chaos ransomware's msaRAT hides command-and-control traffic inside Chrome and Edge browser sessions via WebRTC.
- Researchers disclosed a SharedRoot sandbox escape chain letting Claude Cowork agents reach the host Mac filesystem.
Editorial Analysis
Several of today's flaws share the same underlying weakness: a system validates a condition once, then continues to trust that decision after the underlying state has changed. Although the affected products differ, Gatekeeper, RefluXFS, and SmartConsole each involve a stale trust decision being accepted beyond the point where it remains reliable.
In macOS Gatekeeper, researchers demonstrated that an application marked as trusted after its first execution could later have its executable replaced without triggering the same validation process. RefluXFS abuses a race condition in the Linux kernel's XFS filesystem, where the code re-checks whether a block is still shared using the block reference captured before a lock was dropped, rather than re-reading the file's current state after reacquiring it — allowing another process to remap that block in the interim. Check Point's SmartConsole flaw similarly allowed authentication controls to be bypassed by accepting a session state without sufficient revalidation.
Faster patching remains essential, but it is not a complete answer to failures rooted in system design. These incidents show that some security weaknesses are created not by missing updates, but by incorrect assumptions about trust, validation, and how systems behave when their state changes.
Highlights of the Day
Chaos Ransomware's New RAT Hides C2 Traffic Inside Browser Sessions
Cisco Talos identified msaRAT, a Rust-based remote access trojan linked to the Chaos ransomware group, which hijacks a headless browser via the Chrome DevTools Protocol instead of communicating over the network directly. The malware establishes a WebRTC connection to its command-and-control server, using a Cloudflare Workers endpoint for signalling so that its traffic blends in with legitimate browser activity. Infection begins with an MSI installer disguised as a Windows update, delivered through a curl download to the victim machine.
Check Point Patches Actively Exploited SmartConsole Authentication Bypass
Check Point disclosed CVE-2026-16232, a critical authentication bypass in SmartConsole login affecting Security Management and Multi-Domain Management, rated CVSS 9.3. The flaw has been exploited in the wild against a small number of customers whose Management servers were exposed directly to the internet without IP restrictions. Two further vulnerabilities, an authentication bypass with privilege escalation and a local privilege escalation in GaiaOS WebUI, were also patched with no observed exploitation.
Qualys Uncovers XFS Kernel Flaw Allowing Silent Root Access
Qualys disclosed CVE-2026-64600, a race condition in the Linux kernel's XFS filesystem affecting systems using reflink-enabled volumes, the default since 2019. The flaw lets an unprivileged local user exploit a locking gap during copy-on-write operations to overwrite protected files such as /etc/passwd or SUID-root binaries at the block level. The issue affects kernels since 2017 and was patched on 16 July 2026, with major distributions including RHEL, Rocky, AlmaLinux and Amazon Linux confirmed exposed by default.
Researchers Show macOS Gatekeeper Can Be Bypassed to Swap Apps
Researchers Talal Haj Bakry and Tommy Mysk found a technique letting a local attacker silently replace the main executable of any web-downloaded macOS app after its first run, without elevated privileges. The method archives the trusted app bundle with tar, then restores it as a locally built bundle that bypasses Gatekeeper's revalidation checks. Apple has closed the report, stating the technique falls outside Gatekeeper's intended protections since it produces a locally built app bundle.
Researchers Detail Sandbox Escape Chain in Claude Cowork on macOS
Researchers at Accomplish.ai demonstrated a chain, named SharedRoot, allowing an agent session in Claude Cowork to escape its Linux VM sandbox and reach the host Mac's filesystem. The exploit combines unprivileged user namespaces with CVE-2026-46331, a kernel page-cache poisoning bug, to gain root inside the guest and access a host filesystem mount shared read-write into the VM. Anthropic closed the report as informative, and Cowork now defaults to cloud execution, which the researchers say is not affected by this local escape path.
Russian Group Exploited Zimbra Zero-Day to Steal Government Emails
Proofpoint reported that Russia-aligned actor TA488 exploited CVE-2025-66376, a Zimbra webmail sanitiser flaw, for at least five months before it was patched. The half-click attack required only that a victim open a malicious email, triggering hidden JavaScript that stole credentials, two-factor codes, and up to 90 days of email via DNS exfiltration. Targets included Ukrainian government bodies and US defence, nuclear, and science institutions, with TA488 assessed as linked to Russian intelligence.
Federal Agencies Warn of Widening Attacks on Industrial Controllers
Six U.S. agencies updated a joint advisory warning that attackers are exploiting internet-exposed programmable logic controllers using legitimate engineering software with valid credentials. The July update expands the affected vendors beyond Rockwell Automation to include Schneider Electric and Siemens equipment, and adds detection guidance for tampered shared code modules. Attackers alter controller logic and manipulate operator display screens, and unlike a similar 2023 campaign, this activity has caused confirmed operational disruption and financial loss.
Daily Coverage