{"date_iso":"2026-07-27","date_human":"Monday, July 27, 2026","generated_utc":"2026-07-27 13:00 UTC","read_minutes":3,"patch_tuesday":false,"top_stories":[{"title":"Google goes it alone with a new cybercrime crew taxonomy","link":"https://www.theregister.com/security/2026/07/27/google-goes-it-alone-with-a-new-cybercrime-crew-taxonomy/5278749","reason":"Google","category":"News","sources":["Malwarebytes Labs","The Register Security"],"coverage":2,"cve_ids":[],"summary":"Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=255057&width=800","description":"Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews. The result is a two-word schema in which the first word \u201cis a unique and memorable term chosen to represent the specific actor.\u201d If security\u2026","related":[{"title":"A week in security (July 20 \u2013 July 26)","link":"https://www.malwarebytes.com/blog/news/2026/07/a-week-in-security-july-20-july-26","source":"Malwarebytes Labs","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[{"id":"CVE-2026-16812","vendor":"Arista Networks","product":"Velocloud Orchestrator","severity":"CRITICAL","score":10.0,"description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit\u2026","cwe":"CWE-78","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-07-30","epss":0.0088,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16812"}],"vuln_watch":[{"id":"CVE-2026-12394","vendor":"WordPress","product":"MemberGlut","severity":"CRITICAL","score":9.8,"description":"The MemberGlut  WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compr\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":0.0028,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12394"},{"id":"CVE-2026-13714","vendor":"WordPress","product":"Realtyna Organic IDX plugin + WPL Real Estate","severity":"CRITICAL","score":9.8,"description":"The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardco\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0046,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13714"},{"id":"CVE-2026-64534","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is ca\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-64534"},{"id":"CVE-2026-64535","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":0.0047,"url":"https://cve.blackmesa.ca/?q=CVE-2026-64535"},{"id":"CVE-2026-55971","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.8,"description":"Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":0.0104,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55971"},{"id":"CVE-2026-13332","vendor":"WordPress","product":"Masteriyo LMS","severity":"CRITICAL","score":9.1,"description":"The Masteriyo LMS  WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of an\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13332"},{"id":"CVE-2026-13597","vendor":"WordPress","product":"\u5fae\u4fe1\u4e8c\u7ef4\u7801\u767b\u9646","severity":"CRITICAL","score":9.1,"description":"The \u5fae\u4fe1\u4e8c\u7ef4\u7801\u767b\u9646 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13597"},{"id":"CVE-2026-48144","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-297","kev":false,"kev_action":"","kev_due":"","epss":0.0042,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48144"},{"id":"CVE-2026-58023","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue.","cwe":"CWE-125","kev":false,"kev_action":"","kev_due":"","epss":0.0108,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58023"},{"id":"CVE-2026-58662","vendor":"Apache","product":"Thrift","severity":"CRITICAL","score":9.1,"description":"Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings.\n\nThis issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue\u2026","cwe":"CWE-125","kev":false,"kev_action":"","kev_due":"","epss":0.0115,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58662"}],"vendor_spikes":[{"vendor":"WordPress","count":23,"critical_count":5},{"vendor":"Apache","count":15,"critical_count":4},{"vendor":"Linux","count":6,"critical_count":2},{"vendor":"Microsoft","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":1,"new_cve_count":68,"has_news_data":true,"has_cve_data":true}