CyberPress Weekly – Top 50 Cybersecurity Stories of the Week – Cl0p Windchill Zero-Day, Zimbra Attacks, 23M-User Breach, AI Exploits & More

Welcome to the CyberPress weekly cybersecurity roundup — the 50 stories that defined July 20–24, 2026, organized day by day. This week Cl0p turned a PTC Windchill zero-day into a global data-theft campaign, Russian LAUNDRY BEAR looted 90 days of email through a Zimbra zero-day, and a Paidwork breach exposed 23 million users.

AI kept blurring the line between tool and weapon — OpenAI models chained zero-days against Hugging Face, Kimi K3 found Redis RCE in 27 minutes, and a SharedRoot escape cracked Claude Cowork’s sandbox. Here’s the full briefing.

  MONDAY · JULY 20, 2026

1   CRIME   U.S. Charges Three Russian Nationals in Global Cybercrime Operation Linked to $62 Million in Losses

DOJ indicts a trio tied to $62M in worldwide cyberattack losses.

2   AI   GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain

An AI multi-agent chain autonomously builds a working pre-auth WordPress RCE.

3   MALWARE   North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

OTTERCOOKIE rides inside SVG files in a fresh Contagious Interview wave.

4   VULN   Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts

A default APP_SECRET in Kimai’s Docker image enables admin account takeover.

  TUESDAY · JULY 21, 2026

5   VULN   New Linux Kernel Vulnerabilities Cause Deadlocks, Livelocks, and NULL Pointer Crashes

Fresh kernel bugs trigger deadlocks, livelocks and NULL-pointer crashes.

6   ATTACK   Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access

Qilin affiliates breach networks through a Palo Alto GlobalProtect flaw.

7   BREACH   Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

A Paidwork breach spills banking and personal data on 23 million users.

8   MALWARE   Hackers Use GenAI to Build WebDAV Malware Lab Delivering PureRAT and Credential Stealers

GenAI spins up a WebDAV lab that ships PureRAT and credential stealers.

9   ATTACK   Bit2Watt GPU Attack Uses LLM Training Workloads to Destabilize Data Center Power Grids

Weaponized LLM training loads turn AI data centers into power-grid threats.

  WEDNESDAY · JULY 22, 2026      13 stories  

10   AI   OpenAI Models Chain Zero-Days to Breach Hugging Face During Cyber Evaluation

During a cyber eval, OpenAI models chained zero-days to breach Hugging Face.

11   VULN   Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands

Zimbra 10.1.20 fixes a critical SNMP command-injection flaw.

12   VULN   Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses

Apple patches a bug that unmasked the real address behind Hide My Email.

13   BREACH   Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

An IDOR bug let attackers read other users’ Meta support cases.

14   ATTACK   Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts

Attackers weaponize Microsoft’s device code flow to skip MFA on M365.

15   VULN   Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

CVE-2026-13385 lets MITM attackers push arbitrary commands to ASUS routers.

16   ATTACK   Iran-Linked Hackers Exploit Trusted Access and Exposed OT Systems for Espionage and Disruption

Iran-linked crews build durable access into exposed OT for espionage.

17   VULN   CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE

CISA adds two chained WordPress Core bugs enabling pre-auth RCE to its KEV list.

18   ATTACK   Russian Spies Are Hacking Security Cameras to Track NATO Weapons Shipments

Russian operatives hijack security cameras to watch NATO arms shipments.

19   MALWARE   Fake Camera Troubleshooting Commands Deliver RATs Across Windows and macOS

Bogus ‘camera fix’ commands drop RATs on both Windows and macOS.

20   CRIME   Authorities Dismantle Kratos Phishing-as-a-Service Platform and Seize 200 Servers

Police seize 200 servers and dismantle the Kratos phishing-as-a-service platform.

21   MALWARE   Threat Actors Use Hijacked Teams Accounts in ModeloRAT Attacks

Hijacked Microsoft Teams accounts deliver the stealthy ModeloRAT backdoor.

22   MALWARE   Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers

A Mono-based crypter pairs BYOVD and process ghosting to smuggle RATs past EDR.

  THURSDAY · JULY 23, 2026 ( 8 stories )

23   AI   Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes

A 2.8T-parameter model independently uncovers Redis RCE bugs in 27 minutes.

24   BREACH   Hackers Exploit Security Weaknesses to Compromise South Korean Diplomats’ Personal Data

Attackers harvest personal data belonging to South Korean diplomats.

25   ATTACK   Iranian Hackers Manipulate SCADA Displays After Breaching U.S. Critical Infrastructure PLCs

Iran-linked crews falsify SCADA screens after breaching US PLCs.

26   VULN   Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A malicious RDP server can corrupt heap memory via FreeRDP’s clipboard channel.

27   VULN   Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts

Sangoma patches unauth RCE and admin-takeover flaws in FreePBX.

28   VULN   Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool

An Exim traversal bug leaks files beyond the mail spool on Unix hosts.

29   MALWARE   China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities

An exposed server reveals JadeProx’s TriBack loader hitting public-sector targets.

30   ATTACK   GitHub Actions Abuse Exploits cPanel CVE-2026-41940 to Steal Server Credentials

Abused GitHub Actions exploit a cPanel bypass to steal server secrets at scale.

  FRIDAY · JULY 24, 2026 ( 20 stories ) 

31   ATTACK   Cl0p Exploits PTC Windchill Zero-Day to Deploy Webshells and Steal Data

Cl0p rides Windchill CVE-2026-12569 for unauth RCE, JSP webshells and data theft.

32   ATTACK   Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails

LAUNDRY BEAR abuses a Zimbra zero-day to exfiltrate up to 90 days of email.

33   ATTACK   Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing

Compromised hotel Wi-Fi gateways harvest M365 logins with no phishing needed.

34   BREACH   Origin Energy Confirms Cyberattack Exposed Customers’ Personal and Financial Data

Origin Energy confirms attackers accessed customer personal and financial data.

35   MALWARE   Hackers Use Fake Claude Desktop and Bing Ads to Deliver SectopRAT to 29 Organizations

Fake Claude Desktop ads on Bing push the HVNC-enabled SectopRAT into 29 orgs.

36   MALWARE   New WARDEN Stealer Targets 330+ Apps and 200 Crypto Extensions on Windows

WARDEN MaaS blends credential theft and crypto hijacking across 330+ apps.

37   MALWARE   Golden Chickens TAG-195 Launches TinyEgg and ChonkyChicken Modular Malware

Venom Spider debuts the TinyEgg and ChonkyChicken modular malware families.

38   AI   Claude Cowork SharedRoot Sandbox Escape Exposes Mac Files and Cloud Credentials

A SharedRoot escape lets Claude Cowork content reach Mac files and cloud keys.

39   VULN   Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks

Vercel patches nine Next.js flaws, two critical auth-bypass and SSRF bugs.

40   VULN   Critical IntelliJ IDEA Path Traversal Flaw Enables Code Execution

A path-traversal bug in IntelliJ IDEA enables code execution on a crafted open.

41   VULN   Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code

Low-privilege users can escalate to admin and run code in Apache Syncope.

42   PATCH   Chrome Security Update Fixes Out-of-Bounds Write and Use-After-Free Flaws

Chrome Stable patches high-severity out-of-bounds-write and use-after-free bugs.

43   VULN   NodeBB Patches Eight High-Severity Flaws Enabling XSS, Admin Bypass, and Data Theft

An AI-driven six-hour pentest uncovers eight high-severity NodeBB flaws.

44   MALWARE   Hackers Abuse Service Workers to Assemble Malware Inside Web Browsers

SourTrade assembles malware in-browser using ServiceWorkers and SharedWorkers.

45   MALWARE   Lampion Malware Uses Obfuscated HTML, Multistage VBS and Rundll32 to Deploy 750MB RAT

Lampion hides a 750MB RAT behind obfuscated HTML and multistage VBS in Portugal.

46   MALWARE   Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware

UAC-0099 abuses a legitimate Notepad++ 8.8.3 build to drop MATCHBOIL.V2.

47   MALWARE   Malicious RubyGems Wait Five Hours and Detect Sandboxes Before Starting Monero Mining

Trojanized RubyGems delay five hours and dodge sandboxes to mine Monero.

48   VULN   Microsoft Gets LG to Disable McAfee Pop-Ups From Its Windows Monitor App

After backlash, Microsoft gets LG to kill unsolicited McAfee pop-ups on Windows.

49   ATTACK   Microsoft Warns Phishing Attacks Are Moving Beyond Email Into Workplace Communication Tools

Microsoft warns phishing is shifting into Teams chats and voice calls.

50   CRIME   Illinois Man Pleads Guilty to Phishing Snapchat Codes From Nearly 600 Women

An Illinois man admits phishing login codes from nearly 600 Snapchat users.

  FREQUENTLY ASKED QUESTIONS  

What is the CyberPress weekly cybersecurity roundup?

It’s a once-a-week briefing from CyberPress that gathers the 50 most important cybersecurity stories of the week — vulnerabilities, cyber attacks, data breaches, AI threats and malware — organized day by day with direct links to the full analysis.

How is this different from daily cyber security news?

Instead of tracking headlines all day, you get one prioritized digest. Each story is tagged by category and summarized in a line, so security teams can scan the week in minutes and click through to what matters.

How do I subscribe to CyberPress?

Visit cyberpress.org and follow CyberPress on LinkedIn to receive every weekly roundup. It’s free and lands once a week.

Get the CyberPress weekly roundup in your inbox — free, every week.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Co-Founder & Editor-in-Chief - Cyber Press Inc.,

Trending News

Related Stories