CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (24 July 2026)

Published: Loading…

At a Glance

  • Federal agencies expanded a critical infrastructure advisory to include Iranian exploitation of Siemens, Schneider, and Rockwell PLCs.
  • Check Point patched CVE-2026-16232, a critical SmartConsole authentication bypass exploited against a handful of customers.
  • Qualys disclosed CVE-2026-64600, a nine-year-old XFS race condition giving local users root on default RHEL installs.
  • Russian group Laundry Bear exploited a Zimbra zero-click flaw, CVE-2025-66376, to steal emails and 2FA codes for months.
  • Chaos ransomware's msaRAT hides command-and-control traffic inside Chrome and Edge browser sessions via WebRTC.
  • Researchers disclosed a SharedRoot sandbox escape chain letting Claude Cowork agents reach the host Mac filesystem.

Editorial Analysis

Several of today's flaws share the same underlying weakness: a system validates a condition once, then continues to trust that decision after the underlying state has changed. Although the affected products differ, Gatekeeper, RefluXFS, and SmartConsole each involve a stale trust decision being accepted beyond the point where it remains reliable.

In macOS Gatekeeper, researchers demonstrated that an application marked as trusted after its first execution could later have its executable replaced without triggering the same validation process. RefluXFS abuses a race condition in the Linux kernel's XFS filesystem, where the code re-checks whether a block is still shared using the block reference captured before a lock was dropped, rather than re-reading the file's current state after reacquiring it — allowing another process to remap that block in the interim. Check Point's SmartConsole flaw similarly allowed authentication controls to be bypassed by accepting a session state without sufficient revalidation.

Faster patching remains essential, but it is not a complete answer to failures rooted in system design. These incidents show that some security weaknesses are created not by missing updates, but by incorrect assumptions about trust, validation, and how systems behave when their state changes.

Highlights of the Day

Chaos Ransomware's New RAT Hides C2 Traffic Inside Browser Sessions

Cisco Talos identified msaRAT, a Rust-based remote access trojan linked to the Chaos ransomware group, which hijacks a headless browser via the Chrome DevTools Protocol instead of communicating over the network directly. The malware establishes a WebRTC connection to its command-and-control server, using a Cloudflare Workers endpoint for signalling so that its traffic blends in with legitimate browser activity. Infection begins with an MSI installer disguised as a Windows update, delivered through a curl download to the victim machine.

Check Point Patches Actively Exploited SmartConsole Authentication Bypass

Check Point disclosed CVE-2026-16232, a critical authentication bypass in SmartConsole login affecting Security Management and Multi-Domain Management, rated CVSS 9.3. The flaw has been exploited in the wild against a small number of customers whose Management servers were exposed directly to the internet without IP restrictions. Two further vulnerabilities, an authentication bypass with privilege escalation and a local privilege escalation in GaiaOS WebUI, were also patched with no observed exploitation.

Qualys Uncovers XFS Kernel Flaw Allowing Silent Root Access

Qualys disclosed CVE-2026-64600, a race condition in the Linux kernel's XFS filesystem affecting systems using reflink-enabled volumes, the default since 2019. The flaw lets an unprivileged local user exploit a locking gap during copy-on-write operations to overwrite protected files such as /etc/passwd or SUID-root binaries at the block level. The issue affects kernels since 2017 and was patched on 16 July 2026, with major distributions including RHEL, Rocky, AlmaLinux and Amazon Linux confirmed exposed by default.

Source: Qualys

Researchers Show macOS Gatekeeper Can Be Bypassed to Swap Apps

Researchers Talal Haj Bakry and Tommy Mysk found a technique letting a local attacker silently replace the main executable of any web-downloaded macOS app after its first run, without elevated privileges. The method archives the trusted app bundle with tar, then restores it as a locally built bundle that bypasses Gatekeeper's revalidation checks. Apple has closed the report, stating the technique falls outside Gatekeeper's intended protections since it produces a locally built app bundle.

Researchers Detail Sandbox Escape Chain in Claude Cowork on macOS

Researchers at Accomplish.ai demonstrated a chain, named SharedRoot, allowing an agent session in Claude Cowork to escape its Linux VM sandbox and reach the host Mac's filesystem. The exploit combines unprivileged user namespaces with CVE-2026-46331, a kernel page-cache poisoning bug, to gain root inside the guest and access a host filesystem mount shared read-write into the VM. Anthropic closed the report as informative, and Cowork now defaults to cloud execution, which the researchers say is not affected by this local escape path.

Russian Group Exploited Zimbra Zero-Day to Steal Government Emails

Proofpoint reported that Russia-aligned actor TA488 exploited CVE-2025-66376, a Zimbra webmail sanitiser flaw, for at least five months before it was patched. The half-click attack required only that a victim open a malicious email, triggering hidden JavaScript that stole credentials, two-factor codes, and up to 90 days of email via DNS exfiltration. Targets included Ukrainian government bodies and US defence, nuclear, and science institutions, with TA488 assessed as linked to Russian intelligence.

Source: Proofpoint

Federal Agencies Warn of Widening Attacks on Industrial Controllers

Six U.S. agencies updated a joint advisory warning that attackers are exploiting internet-exposed programmable logic controllers using legitimate engineering software with valid credentials. The July update expands the affected vendors beyond Rockwell Automation to include Schneider Electric and Siemens equipment, and adds detection guidance for tampered shared code modules. Attackers alter controller logic and manipulate operator display screens, and unlike a similar 2023 campaign, this activity has caused confirmed operational disruption and financial loss.

Daily Coverage

Developments
CVE-2026-16232 ExploitedRefluxfs Root FlawLaundry Bear Zimbra CampaignMsarat Browser C2
Vulnerabilities
CVE-2026-16232Quantum Security Management R82.10 With Jumbo Hotfix Take 36 Or BelowCVE-2026-64600Linux 3C68D44A2B49A0Ac9165Faa9C191E1E618C8A8D5CVE-2025-66376Collaboration 10.0 (High)CVE-2026-63030Wordpress 6.9.0 (Critical)CVE-2026-60137Wordpress 6.8.0 (Medium)CVE-2026-48294Adobe Acrobat Pdf Extension (Chrome) (High)CVE-2026-46331Linux 8B796475Fd7882663A870456466A4Fb315Cc1Bd6CVE-2026-50522Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Critical)CVE-2026-32201Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Medium)CVE-2026-45659Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.