{"date_iso":"2026-07-28","date_human":"Tuesday, July 28, 2026","generated_utc":"2026-07-28 13:00 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost","link":"https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html","reason":"Microsoft","category":"News","sources":["Ars Technica Security","CCCS Alerts & Advisories","Infosecurity Magazine","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwmG858LYHQA-u4cQupdhqsi5oUcvLaQdoorupsW3tzPZvDg7kwgRIewOBPVNvp3Szfqb4VFJ_j6caul2NTIlm69_-vskp4gYQwVkQA59LbsMhOEO3yr4C48nhrO177ORbi9uFc_oIOrcXnCBs_dmPhVDZVZx9F3Cyp4RQKi71EhvfZQqmUKat36cbqEE/s1600/MAI-Cyber-1-Flash.jpg","description":"Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved","related":[{"title":"Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats","link":"https://www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/","source":"Infosecurity Magazine","date_rel":"15m ago"},{"title":"Chaos in Teams vishing","link":"https://www.sophos.com/en-us/blog/chaos-in-teams-vishing","source":"Sophos Threat Research","date_rel":"13h ago"},{"title":"Microsoft unveils AI security tools it says outperform competing platforms","link":"https://arstechnica.com/security/2026/07/microsoft-unveils-ai-security-tools-it-says-outperform-competing-platforms/","source":"Ars Technica Security","date_rel":"15h ago"},{"title":"Microsoft's solution to AI security: more AI and more acronyms","link":"https://www.theregister.com/security/2026/07/27/microsofts-solution-to-ai-security-more-ai-and-more-acronyms/5279140","source":"The Register Security","date_rel":"17h ago"},{"title":"Microsoft security advisory (AV26-747)","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-av26-747","source":"CCCS Alerts & Advisories","date_rel":"19h ago"}]},{"title":"Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit","link":"https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html","reason":"Linux","category":"News","sources":["CISA Alerts & Advisories","CISA ICS Advisories","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-53264"],"summary":"STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgBRFXQr7hvRBIkSC-vqaka7UlRsU8Y380TbDC3jFpFlSlCK1RuVthJDLKt5KaNzAn82kMBNUWPp5s1Voug8ptjn0DiHoxbzw9QdoKXhFfR9SR9zCm1uYeE43tZUba0H7F-mlLogft-qyvtdggSASBR8qAxrRK3U3uPzvf_bkRmJPNzcWX-vfb7qW0VD8/s1600/linux.jpg","description":"STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local","related":[{"title":"Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04","source":"CISA Alerts & Advisories","date_rel":"1h ago"},{"title":"Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04","source":"CISA ICS Advisories","date_rel":"1h ago"},{"title":"Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update","link":"https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpoint-leaves-some-linux-boxes-defenseless-after-update/5278914","source":"The Register Security","date_rel":"23h ago"}]},{"title":"Tons of Peoples\u2019 Claude Chats and Creations are Exposed on Google","link":"https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/","reason":"Google","category":"News","sources":["404 Media","Dark Reading","Malwarebytes Labs"],"coverage":3,"cve_ids":[],"summary":"Claude is exposing a wealth of users\u2019 chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly\u2026","source":"404 Media","date_rel":"23h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/brett-wharton-YmSiFKOecCU-unsplash.jpg","description":"Claude is exposing a wealth of users\u2019 chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see.","related":[{"title":"Shared Claude chats were searchable on Google","link":"https://www.malwarebytes.com/blog/privacy/2026/07/shared-claude-chats-were-searchable-on-google","source":"Malwarebytes Labs","date_rel":"26m ago"},{"title":"'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure","link":"https://www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure","source":"Dark Reading","date_rel":"16h ago"},{"title":"Aftercall ads are driving Android users crazy","link":"https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy","source":"Malwarebytes Labs","date_rel":"17h ago"}]},{"title":"ABB KNX Update Tool","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07","reason":"Abb","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX\u2026","related":[{"title":"ABB KNX Update Tool","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Siemens Desigo CC","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","reason":"Openssl","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected: Desigo CC family V7 vers:all/* (CVE-2025-15467) Desigo CC family V8 vers:all/* (CVE-2025-15467) Desigo\u2026","related":[{"title":"Siemens Desigo CC","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Siemens SIMATIC S7-PLCSIM Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03","reason":"Siemens","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical\u2026","related":[{"title":"Siemens Mendix Runtime","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02","source":"CISA Alerts & Advisories","date_rel":"1h ago"},{"title":"Siemens SIMATIC S7-PLCSIM Advanced","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03","source":"CISA ICS Advisories","date_rel":"1h ago"},{"title":"Siemens Mendix Runtime","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"igloohome Smart Lock Mobile Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06","reason":"Application Igloohome Mobile","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected: Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581) CVSS Vendor Equipment Vulnerabilities v3 5.3 igloohome igloohome Smart Lock Mobile Application Inclusion of Sensitive Information in Source Code Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: Singapore Vulnerabilities Expand All +\u2026","related":[{"title":"igloohome Smart Lock Mobile Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"MikroTik RouterOS and Cloud Hosted Router","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05","reason":"Routeros Mikrotik Hosted","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router are affected: RouterOS vers:all/* (CVE-2026-16347) Cloud Hosted Router vers:all/* (CVE-2026-16347) CVSS Vendor Equipment Vulnerabilities v3 8.8 MikroTik MikroTik RouterOS and Cloud Hosted Router Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Information Technology, Commercial Facilities Countries/Areas Deployed: Worldwide\u2026","related":[{"title":"MikroTik RouterOS and Cloud Hosted Router","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock","link":"https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414","reason":"CVE-2026-16812","category":"News","sources":["The Hacker News","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-16812"],"summary":"A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812\u2026","source":"The Register Security","date_rel":"3h ago","thumbnail":"https://image.theregister.com/?imageId=5279434&width=800","description":"A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments. According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows\u2026","related":[{"title":"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw","link":"https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html","source":"The Hacker News","date_rel":"8h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-16812","vendor":"Arista Networks","product":"Velocloud Orchestrator","severity":"CRITICAL","score":10.0,"description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit\u2026","cwe":"CWE-78","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-07-30","epss":0.0088,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16812"},{"id":"CVE-2026-11756","vendor":"Dassault Syst\u00e8mes","product":"Station Launcher App in 3DEXPERIENCE platform","severity":"CRITICAL","score":10.0,"description":"A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0045,"url":"https://cve.blackmesa.ca/?q=CVE-2026-11756"},{"id":"CVE-2026-48030","vendor":"pheditor","product":"pheditor","severity":"CRITICAL","score":9.9,"description":"Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS command\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.0155,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48030"},{"id":"CVE-2026-61511","vendor":"vBulletin","product":"vBulletin","severity":"CRITICAL","score":9.8,"description":"vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":0.0127,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61511"},{"id":"CVE-2026-65879","vendor":"joomshaper.com","product":"SP Page Builder extension for Joomla","severity":"CRITICAL","score":9.8,"description":"Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.0028,"url":"https://cve.blackmesa.ca/?q=CVE-2026-65879"},{"id":"CVE-2026-51303","vendor":"Apple","product":"","severity":"CRITICAL","score":9.8,"description":"A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an ExprList object via sqlite3ExprListDelete and then subsequently accesses the dangling pointer of \u2026","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":0.0037,"url":"https://cve.blackmesa.ca/?q=CVE-2026-51303"},{"id":"CVE-2026-63077","vendor":"JetBrains","product":"TeamCity","severity":"CRITICAL","score":9.8,"description":"In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0065,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63077"},{"id":"CVE-2026-55579","vendor":"pheditor","product":"pheditor","severity":"CRITICAL","score":9.8,"description":"Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a \u2026","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","epss":0.006,"url":"https://cve.blackmesa.ca/?q=CVE-2026-55579"},{"id":"CVE-2026-28911","vendor":"Apple","product":"Macos","severity":"CRITICAL","score":9.8,"description":"The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28911"},{"id":"CVE-2026-28928","vendor":"Apple","product":"Ipados","severity":"CRITICAL","score":9.8,"description":"A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":0.0042,"url":"https://cve.blackmesa.ca/?q=CVE-2026-28928"}],"vendor_spikes":[{"vendor":"Apple","count":167,"critical_count":56},{"vendor":"WordPress","count":45,"critical_count":3},{"vendor":"Linux","count":19,"critical_count":2},{"vendor":"Unknown","count":13,"critical_count":3},{"vendor":"jfrog","count":11,"critical_count":0},{"vendor":"Red Hat","count":8,"critical_count":0},{"vendor":"vercel","count":8,"critical_count":0},{"vendor":"Progress","count":5,"critical_count":0},{"vendor":"joomshaper.com","count":5,"critical_count":1},{"vendor":"Microsoft","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":452,"has_news_data":true,"has_cve_data":true}