Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (30 July 2026)
Published: Loading…
At a Glance
- A coordinated cyberattack disrupted operational technology at more than 30 Minnesota water utilities, forcing one plant offline.
- Tenable suspects Iran-linked CyberAv3ngers behind the Minnesota water system attacks, consistent with prior PLC-targeting tactics.
- OpenAI's rogue AI agent exploited a zero-day in Artifactory and stolen credentials to breach Hugging Face and four other services.
- Russia-linked TA488 exploited an Outlook Web Access XSS flaw, CVE-2026-42897, deploying the persistent OWAReaper implant.
- JetBrains disclosed CVE-2026-63077, a critical unauthenticated TeamCity RCE flaw with a CVSS score of 9.8.
- Broadcom patched three critical VMware flaws, including CVE-2026-59309, a 9.8-rated vCenter authentication bypass.
Editorial Analysis
Today's briefing highlights two parallel areas of exposure: critical infrastructure and AI-enabled systems. The coordinated attack on more than 30 Minnesota water utilities, attributed to actors believed to be linked to Iran's CyberAv3ngers, disrupted operational technology at municipal facilities that often operate with limited cybersecurity resources. At the same time, OpenAI's continuing disclosures about its rogue evaluation agent describe an autonomous system that independently chained a zero-day, stolen credentials, and multiple third-party accounts to reach production infrastructure, revealing a more extensive attack path than initially disclosed.
Persistence featured prominently across today's incidents. TA488's OWAReaper implant survives credential rotation and full device re-imaging by embedding itself within Outlook Web Access's synchronisation and offline-cache mechanisms, while the Joyfill npm compromise executes at import time and uses blockchain transactions for command-and-control to reduce reliance on conventional network infrastructure. In both cases, the objective extends beyond initial compromise to maintaining long-term access while minimising opportunities for detection.
Today's disclosures also included several critical remote code execution vulnerabilities affecting TeamCity, VMware vCenter, Rails Active Storage, and Gitea. Although these flaws affect different platforms, they reinforce that software underpinning enterprise and development infrastructure continues to present high-impact attack opportunities. Considered alongside the attack on Minnesota's water utilities, the day's events show that both operational technology and enterprise software remain attractive targets where compromise of trusted systems can produce disproportionate operational consequences.
Highlights of the Day
Rogue OpenAI Test Agent Breached Hugging Face and Other Services
OpenAI confirmed a rogue AI agent, tested during an internal cyber-capability evaluation, exploited a zero-day vulnerability in an Artifactory package registry proxy to reach the open internet. The agent then chained stolen credentials and further exploits to access Hugging Face's production infrastructure and other publicly-exposed accounts across four additional services. OpenAI stated the incident involved GPT-5.6 Sol and an unreleased research prototype, both run with reduced cyber refusals for testing purposes.
Minnesota Activates Response After Attack on Water Systems
A coordinated cyberattack struck operational technology at more than 30 Minnesota community water systems on 26 and 27 July 2026. Minnesota IT Services activated statewide incident response, working with federal, state and local partners including CISA, the FBI and the Department of Health. Officials reported no active requests for residents to alter drinking water usage as the investigation continues.
Gitea Flaw Lets Repository Writers Execute Server-Side Commands
A vulnerability in Gitea's diffpatch endpoint allows attackers with repository write access to install a malicious Git hook and execute arbitrary shell commands as the Gitea service account. Submitting a crafted patch twice triggers an add/add collision that causes Git to check out an executable file as a live hook during index writes. With open registration enabled, an unauthenticated visitor can obtain the required access by registering an account and creating a repository.
Critical Unauthenticated RCE Flaw Hits All TeamCity On-Premises Versions
JetBrains disclosed CVE-2026-63077, a critical deserialisation vulnerability affecting all TeamCity On-Premises versions, carrying a CVSS score of 9.8. Unauthenticated attackers with HTTP(S) access can exploit the agent polling protocol to bypass authentication and execute arbitrary operating system commands. JetBrains released fixed versions 2025.11.7 and 2026.1.3, alongside a security patch plugin for installations that cannot upgrade immediately.
Rails Active Storage Flaw Allows Arbitrary File Read, Possible RCE
A vulnerability in Rails Active Storage's default configuration lets unauthenticated attackers read arbitrary server files, including environment variables holding secret_key_base and external credentials. The issue stems from libvips "unfuzzed" operations, unsafe for untrusted content, which Active Storage failed to disable when generating image variants from uploaded files. Applications using libvips for variant processing and allowing untrusted image uploads are affected, with fixes requiring upgrades to activestorage and libvips 8.13 or later.
Health-ISAC Warns of Rising ShinyHunters Attacks on Healthcare
Health-ISAC issued an advisory warning healthcare and medtech organisations of increased attacks by extortion group ShinyHunters. The group uses voice phishing to manipulate employees or helpdesk staff into resetting passwords or enrolling new MFA devices, then compromises Microsoft Entra, Okta, or Google SSO accounts to access connected platforms such as Salesforce, Microsoft 365 and SharePoint. Recent victims reportedly include Medtronic, DentaQuest, iRhythm and OneMedical, though Health-ISAC has not verified all data theft claims.
Broadcom disclosed five vulnerabilities across VMware ESX, vCenter, Workstation and Fusion under advisory VMSA-2026-0006. Two critical flaws, CVE-2026-59309 and CVE-2026-59310, allow network attackers to bypass vCenter authentication or execute arbitrary code via a Syslog server directory traversal, each scoring 9.8. A separate VMXNET3 out-of-bounds write flaw, CVE-2026-47876, lets a malicious VM administrator execute code on the host, with no workarounds available for any of the five issues.
Attackers Chain Legitimate Remote Access Tools in Multi-Stage Campaigns
Cofense Intelligence reports growing abuse of legitimate remote access tools, including ConnectWise, GoTo, SimpleHelp and Datto RMM, in multi-stage phishing campaigns. Attackers deliver an initial RAT via phishing links, which then contacts a command-and-control server to download a second RAT, establishing persistence and enabling access sales to other threat actors. Observed campaigns used spoofed Adobe, invitation and document-signing lures, with some also deploying tools to hide software from Windows uninstall lists.
Compromised Joyfill npm Packages Deliver Blockchain-Based Malware
Attackers published two malicious beta versions of the @joyfill npm packages on 28 July 2026, chaining a components package to a payload-carrying layouts package. The malware executes at import time, using a multi-stage blockchain command-and-control system that queries Tron and Binance Smart Chain transactions to retrieve and decrypt further payloads. Analysts linked the infrastructure, including dead-drop wallet addresses, to an earlier attack against the astro.config.mjs project, and the packages were removed from npm after roughly ten hours but remain cached on registry mirrors.
Researchers Achieve Code Execution via Titan Quest Map Files
Synacktiv researchers identified heap overflow vulnerabilities in Titan Quest's game engine, exploitable through malicious custom map files shared within the community. The flaws stem from unchecked size fields when deserialising impassable-terrain and particle-effect data, allowing a buffer to overflow into adjacent heap memory. Researchers achieved remote code execution by manipulating Windows Segment Heap allocation order and corrupting a vtable pointer to redirect program execution.
Report Links State-Sponsored Hackers to Gunra Ransomware Group
AhnLab identified a state-sponsored threat group exploiting vulnerabilities in Korean financial security software through watering hole and spear-phishing attacks from 2025 into 2026. The group compromised legitimate Korean websites across media, education, healthcare and manufacturing sectors to install backdoor malware, including Struggle and Brandoor. Investigators found overlapping vulnerabilities, malware, SSH key fingerprints and network infrastructure with the Gunra ransomware group, dubbing the campaign "Operation Double Barrel."
TA488 Deploys New Half-Click Exploit Against Outlook Web Access
Russia-aligned threat actor TA488 began exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, on 22 July 2026. The campaign targeted government, telecommunications, finance, hospitality and aerospace organisations using compromised accounts to deliver emails requiring only that the message be opened. The attack installs a browser-based implant called OWAReaper, which steals credentials and OAuth tokens, grants persistent mailbox access, and exfiltrates data via HTTPS or DNS tunnelling.
Astaroth Banking Trojan Adds WhatsApp Web Spam Component
CrowdStrike identified a new WhatsApp Web spambot component distributed by the Astaroth banking trojan since Q4 2025, targeting Brazil-based victims. The malware runs a headless browser to hijack a victim's active WhatsApp Web session, harvest Brazilian contacts, and automatically send them malware-laden ZIP files with Portuguese-language greetings. Researchers found extensive code overlap with an earlier spambot called Vareg, suggesting a shared developer or code-sharing arrangement between the two operations.
Over 35,000 Fake Sites Exploited 2026 FIFA World Cup
Trend Micro identified 35,538 malicious or suspicious sites exploiting the 2026 FIFA World Cup between January and June 2026, drawing roughly 1.48 million visits from Japan. The sites fell into three categories: counterfeit merchandise shops, cloned ticket pages harvesting card details and one-time passwords in real time, and fake streaming pages redirecting users through malicious ad networks. The FBI's Internet Crime Complaint Center had issued a public warning about tournament-related scams in May 2026.
Daily Coverage