Welcome to the CyberPress weekly cybersecurity roundup — the 50 stories that defined July 20–24, 2026, organized day by day. This week Cl0p turned a PTC Windchill zero-day into a global data-theft campaign, Russian LAUNDRY BEAR looted 90 days of email through a Zimbra zero-day, and a Paidwork breach exposed 23 million users.
AI kept blurring the line between tool and weapon — OpenAI models chained zero-days against Hugging Face, Kimi K3 found Redis RCE in 27 minutes, and a SharedRoot escape cracked Claude Cowork’s sandbox. Here’s the full briefing.
MONDAY · JULY 20, 2026
1 CRIME U.S. Charges Three Russian Nationals in Global Cybercrime Operation Linked to $62 Million in Losses
DOJ indicts a trio tied to $62M in worldwide cyberattack losses.
2 AI GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain
An AI multi-agent chain autonomously builds a working pre-auth WordPress RCE.
3 MALWARE North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
OTTERCOOKIE rides inside SVG files in a fresh Contagious Interview wave.
4 VULN Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts
A default APP_SECRET in Kimai’s Docker image enables admin account takeover.
TUESDAY · JULY 21, 2026
5 VULN New Linux Kernel Vulnerabilities Cause Deadlocks, Livelocks, and NULL Pointer Crashes
Fresh kernel bugs trigger deadlocks, livelocks and NULL-pointer crashes.
6 ATTACK Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access
Qilin affiliates breach networks through a Palo Alto GlobalProtect flaw.
7 BREACH Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
A Paidwork breach spills banking and personal data on 23 million users.
8 MALWARE Hackers Use GenAI to Build WebDAV Malware Lab Delivering PureRAT and Credential Stealers
GenAI spins up a WebDAV lab that ships PureRAT and credential stealers.
9 ATTACK Bit2Watt GPU Attack Uses LLM Training Workloads to Destabilize Data Center Power Grids
Weaponized LLM training loads turn AI data centers into power-grid threats.
WEDNESDAY · JULY 22, 2026 13 stories
10 AI OpenAI Models Chain Zero-Days to Breach Hugging Face During Cyber Evaluation
During a cyber eval, OpenAI models chained zero-days to breach Hugging Face.
11 VULN Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands
Zimbra 10.1.20 fixes a critical SNMP command-injection flaw.
12 VULN Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses
Apple patches a bug that unmasked the real address behind Hide My Email.
13 BREACH Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
An IDOR bug let attackers read other users’ Meta support cases.
14 ATTACK Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts
Attackers weaponize Microsoft’s device code flow to skip MFA on M365.
15 VULN Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
CVE-2026-13385 lets MITM attackers push arbitrary commands to ASUS routers.
16 ATTACK Iran-Linked Hackers Exploit Trusted Access and Exposed OT Systems for Espionage and Disruption
Iran-linked crews build durable access into exposed OT for espionage.
17 VULN CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE
CISA adds two chained WordPress Core bugs enabling pre-auth RCE to its KEV list.
18 ATTACK Russian Spies Are Hacking Security Cameras to Track NATO Weapons Shipments
Russian operatives hijack security cameras to watch NATO arms shipments.
19 MALWARE Fake Camera Troubleshooting Commands Deliver RATs Across Windows and macOS
Bogus ‘camera fix’ commands drop RATs on both Windows and macOS.
20 CRIME Authorities Dismantle Kratos Phishing-as-a-Service Platform and Seize 200 Servers
Police seize 200 servers and dismantle the Kratos phishing-as-a-service platform.
21 MALWARE Threat Actors Use Hijacked Teams Accounts in ModeloRAT Attacks
Hijacked Microsoft Teams accounts deliver the stealthy ModeloRAT backdoor.
22 MALWARE Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers
A Mono-based crypter pairs BYOVD and process ghosting to smuggle RATs past EDR.
THURSDAY · JULY 23, 2026 ( 8 stories )
23 AI Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes
A 2.8T-parameter model independently uncovers Redis RCE bugs in 27 minutes.
24 BREACH Hackers Exploit Security Weaknesses to Compromise South Korean Diplomats’ Personal Data
Attackers harvest personal data belonging to South Korean diplomats.
25 ATTACK Iranian Hackers Manipulate SCADA Displays After Breaching U.S. Critical Infrastructure PLCs
Iran-linked crews falsify SCADA screens after breaching US PLCs.
26 VULN Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code
A malicious RDP server can corrupt heap memory via FreeRDP’s clipboard channel.
27 VULN Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts
Sangoma patches unauth RCE and admin-takeover flaws in FreePBX.
28 VULN Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool
An Exim traversal bug leaks files beyond the mail spool on Unix hosts.
29 MALWARE China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities
An exposed server reveals JadeProx’s TriBack loader hitting public-sector targets.
30 ATTACK GitHub Actions Abuse Exploits cPanel CVE-2026-41940 to Steal Server Credentials
Abused GitHub Actions exploit a cPanel bypass to steal server secrets at scale.
FRIDAY · JULY 24, 2026 ( 20 stories )
31 ATTACK Cl0p Exploits PTC Windchill Zero-Day to Deploy Webshells and Steal Data
Cl0p rides Windchill CVE-2026-12569 for unauth RCE, JSP webshells and data theft.
32 ATTACK Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
LAUNDRY BEAR abuses a Zimbra zero-day to exfiltrate up to 90 days of email.
33 ATTACK Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing
Compromised hotel Wi-Fi gateways harvest M365 logins with no phishing needed.
34 BREACH Origin Energy Confirms Cyberattack Exposed Customers’ Personal and Financial Data
Origin Energy confirms attackers accessed customer personal and financial data.
35 MALWARE Hackers Use Fake Claude Desktop and Bing Ads to Deliver SectopRAT to 29 Organizations
Fake Claude Desktop ads on Bing push the HVNC-enabled SectopRAT into 29 orgs.
36 MALWARE New WARDEN Stealer Targets 330+ Apps and 200 Crypto Extensions on Windows
WARDEN MaaS blends credential theft and crypto hijacking across 330+ apps.
37 MALWARE Golden Chickens TAG-195 Launches TinyEgg and ChonkyChicken Modular Malware
Venom Spider debuts the TinyEgg and ChonkyChicken modular malware families.
38 AI Claude Cowork SharedRoot Sandbox Escape Exposes Mac Files and Cloud Credentials
A SharedRoot escape lets Claude Cowork content reach Mac files and cloud keys.
39 VULN Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks
Vercel patches nine Next.js flaws, two critical auth-bypass and SSRF bugs.
40 VULN Critical IntelliJ IDEA Path Traversal Flaw Enables Code Execution
A path-traversal bug in IntelliJ IDEA enables code execution on a crafted open.
41 VULN Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Low-privilege users can escalate to admin and run code in Apache Syncope.
42 PATCH Chrome Security Update Fixes Out-of-Bounds Write and Use-After-Free Flaws
Chrome Stable patches high-severity out-of-bounds-write and use-after-free bugs.
43 VULN NodeBB Patches Eight High-Severity Flaws Enabling XSS, Admin Bypass, and Data Theft
An AI-driven six-hour pentest uncovers eight high-severity NodeBB flaws.
44 MALWARE Hackers Abuse Service Workers to Assemble Malware Inside Web Browsers
SourTrade assembles malware in-browser using ServiceWorkers and SharedWorkers.
45 MALWARE Lampion Malware Uses Obfuscated HTML, Multistage VBS and Rundll32 to Deploy 750MB RAT
Lampion hides a 750MB RAT behind obfuscated HTML and multistage VBS in Portugal.
46 MALWARE Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware
UAC-0099 abuses a legitimate Notepad++ 8.8.3 build to drop MATCHBOIL.V2.
47 MALWARE Malicious RubyGems Wait Five Hours and Detect Sandboxes Before Starting Monero Mining
Trojanized RubyGems delay five hours and dodge sandboxes to mine Monero.
48 VULN Microsoft Gets LG to Disable McAfee Pop-Ups From Its Windows Monitor App
After backlash, Microsoft gets LG to kill unsolicited McAfee pop-ups on Windows.
49 ATTACK Microsoft Warns Phishing Attacks Are Moving Beyond Email Into Workplace Communication Tools
Microsoft warns phishing is shifting into Teams chats and voice calls.
50 CRIME Illinois Man Pleads Guilty to Phishing Snapchat Codes From Nearly 600 Women
An Illinois man admits phishing login codes from nearly 600 Snapchat users.
FREQUENTLY ASKED QUESTIONS
What is the CyberPress weekly cybersecurity roundup?
It’s a once-a-week briefing from CyberPress that gathers the 50 most important cybersecurity stories of the week — vulnerabilities, cyber attacks, data breaches, AI threats and malware — organized day by day with direct links to the full analysis.
How is this different from daily cyber security news?
Instead of tracking headlines all day, you get one prioritized digest. Each story is tagged by category and summarized in a line, so security teams can scan the week in minutes and click through to what matters.
How do I subscribe to CyberPress?
Visit cyberpress.org and follow CyberPress on LinkedIn to receive every weekly roundup. It’s free and lands once a week.
Get the CyberPress weekly roundup in your inbox — free, every week.