{"date_iso":"2026-07-29","date_human":"Wednesday, July 29, 2026","generated_utc":"2026-07-29 13:00 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Apple\u2019s iMessage Scanning Flagged a Video of My Friend's Dog as Nudity","link":"https://www.404media.co/apples-imessage-scanning-flagged-a-video-of-my-friends-dog-as-nudity/","reason":"Apple","category":"News","sources":["404 Media","CCCS Alerts & Advisories","SANS Internet Storm Center","Zero Day Initiative"],"coverage":4,"cve_ids":[],"summary":"In a video my friend\u2019s dog is laying on her back, her little paws in the air, while my friend rubs the dog\u2019s chest. You can see most of the dog \u2014 who I\u2019m not naming for very important privacy reasons \u2014 from her head to\u2026","source":"404 Media","date_rel":"22h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/07/dog-redact.png","description":"In a video my friend\u2019s dog is laying on her back, her little paws in the air, while my friend rubs the dog\u2019s chest. You can see most of the dog \u2014 who I\u2019m not naming for very important privacy reasons \u2014 from her head to her belly. On closer inspection, you\u2019ll notice the picture includes some dog nipples. Apple\u2019s iMessage thought this video was so inappropriate that it flagged the video as potentially containing nudity and blurred it. When someone else received the video over iMessage, the app displayed the message \u201cThis may be sensitive.\u201d They had to purposefully tap to reveal the video of a\u2026","related":[{"title":"Apple Patches Everything (July 2026), (Wed, Jul 29th)","link":"https://isc.sans.edu/diary/rss/33196","source":"SANS Internet Storm Center","date_rel":"5h ago"},{"title":"ZDI-26-494: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-494/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"ZDI-26-493: Apple macOS USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-493/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"ZDI-26-492: Apple macOS ImageIO Numeric Truncation Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-492/","source":"Zero Day Initiative","date_rel":"8h ago"},{"title":"Apple security advisory (AV26-753)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-753","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"MCP gets an enterprise makeover","link":"https://www.theregister.com/ai-and-ml/2026/07/29/mcp-gets-an-enterprise-makeover/5280027","reason":"Linux","category":"News","sources":["Infosecurity Magazine","Schneier on Security","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024\u2026","source":"The Register Security","date_rel":"13h ago","thumbnail":"https://image.theregister.com/?imageId=5239946&width=800","description":"The Agentic AI Foundation, part of the Linux Foundation, has released an update to the Model Context Protocol (MCP) that aims to help enterprises adopt AI-based automation. Open-sourced by Anthropic in November 2024, MCP provides a way for AI applications (agents) based on models like GPT-5.6 Sol or Claude Opus 5 to connect to existing data sources, tools, or other applications. It defines how content is exchanged in a client-server architecture. \"The new release is MCP\u2019s most important since remote MCP first launched over a year ago,\" wrote David Soria Parra, a member of technical staff at\u2026","related":[{"title":"Long-Lived Vulnerability in Microsoft Secure Boot","link":"https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html","source":"Schneier on Security","date_rel":"1h ago"},{"title":"Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process","link":"https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html","source":"The Hacker News","date_rel":"21h ago"},{"title":"AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched","link":"https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/","source":"Infosecurity Magazine","date_rel":"22h ago"}]},{"title":"Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here","link":"https://www.elastic.co/security-labs/sentinel-detection-rules-migration","reason":"Microsoft","category":"Research","sources":["Dark Reading","Elastic Security Labs","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping\u2026","source":"Elastic Security Labs","date_rel":"13h ago","thumbnail":"https://www.elastic.co/security-labs/assets/images/sentinel-detection-rules-migration/image4.jpg","description":"Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer to where your data lives. Which Microsoft Sentinel rule types can be migrated automatically?\u2026","related":[{"title":"Microsoft and Wiz mind-meld agents catch more than 90% of bugs","link":"https://www.theregister.com/security/2026/07/28/microsoft-and-wiz-mind-meld-agents-catch-more-than-90-of-bugs/5279914","source":"The Register Security","date_rel":"17h ago"},{"title":"'Certighost' Flaw Haunts Microsoft Active Directory Certificates","link":"https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates","source":"Dark Reading","date_rel":"20h ago"}]},{"title":"73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack","link":"https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html","reason":"Teams","category":"News","sources":["CrowdStrike Blog","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixbolkSzPCa__qy94Mm27YfEsvVeyY94SOG5BrCQCGtAe-QenE0qDM5Tkbb7eOy0PwSCECFGMrZ7IG7lVePoMWjqMn8s_7-5_r8JUSQ7WVHsHAo-zZIhyphenhyphenyNW5aGTbFkpgtu99ucSeEgcJK75UdxkAsWKjXf_x8zEGpcDURPf9UJjcDz8JSHFD0uahDcOI5/s1600/ss.jpg","description":"Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January","related":[{"title":"Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud","link":"https://www.crowdstrike.com/en-us/blog/new-in-falcon-cloud-security-helping-security-teams-move-faster/","source":"CrowdStrike Blog","date_rel":"8h ago"}]},{"title":"Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass","link":"https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html","reason":"Check Point","category":"News","sources":["Rapid7 Blog","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-16232"],"summary":"Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIxq_zUC231fexQTfY9VPvqP7FWVRurT9fbUUS3YMpMX2SRmJu9eXIlH7v6fnvqJGtirQwXJVjs1h-hbUM7j-R6DlfpW7M4kt28q9EoxMt7jJFjUjaAoVsuTWSsBZOFcDj99U8ApvFR4B4sDQ37QHYeWXjJsowFBP3n8-TBfzcKB2Rl-de-OluIkzbJIYb/s1600/cp-poc.jpg","description":"Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that","related":[{"title":"Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)","link":"https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232","source":"Rapid7 Blog","date_rel":"18h ago"}]}],"worth_reading":[],"kev_watch":[{"id":"CVE-2026-20316","vendor":"Cisco","product":"Secure Firewall Management Center","severity":"MEDIUM","score":5.3,"description":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th\u2026","cwe":"CWE-259","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-08-01","epss":0.0079,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20316"}],"vuln_watch":[{"id":"CVE-2026-16498","vendor":"HashiCorp","product":"Tooling","severity":"CRITICAL","score":10.0,"description":"The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of sub\u2026","cwe":"CWE-488","kev":false,"kev_action":"","kev_due":"","epss":0.0033,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16498"},{"id":"CVE-2026-33267","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Improper Input Validation vulnerability in Apache Traffic Server.\n\nThis issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes t\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-33267"},{"id":"CVE-2026-57834","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Apache Traffic Server allows request smuggling if chunked messages are malformed.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers are recommended to upgrade \u2026","cwe":"CWE-444","kev":false,"kev_action":"","kev_due":"","epss":0.0026,"url":"https://cve.blackmesa.ca/?q=CVE-2026-57834"},{"id":"CVE-2026-58150","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nU\u2026","cwe":"CWE-444","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58150"},{"id":"CVE-2026-58162","vendor":"Apache","product":"Apache Traffic Server","severity":"CRITICAL","score":10.0,"description":"The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\nUsers ar\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58162"},{"id":"CVE-2026-63227","vendor":"An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"An unrestricted SCORM file upload vulnerability\nin Koollab LMS allowed\nan authenticated module designer to upload a SCORM package containing a PHP\nwebshell to a publicly accessible directory and execute arbitrary code on the\nserver.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":0.0033,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63227"},{"id":"CVE-2026-63232","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment\nreinforcement endpoint, control data passed to unserialize(), write a webshell\nto a publicly accessib\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63232"},{"id":"CVE-2026-63233","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment\noverall answer endpoint, control data passed to unserialize(), write a webshell\nto a publicly accessi\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63233"},{"id":"CVE-2026-63234","vendor":"Three Learning","product":"Koollab LMS","severity":"CRITICAL","score":9.9,"description":"A SQL injection and unsafe deserialisation\nvulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark\nassessment endpoint, control data passed to unserialize(), write a webshell to\na publicly accessible\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-63234"},{"id":"CVE-2026-51252","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.","cwe":"CWE-120","kev":false,"kev_action":"","kev_due":"","epss":0.0034,"url":"https://cve.blackmesa.ca/?q=CVE-2026-51252"}],"vendor_spikes":[{"vendor":"Apache","count":45,"critical_count":8},{"vendor":"WordPress","count":39,"critical_count":5},{"vendor":"IBM","count":31,"critical_count":5},{"vendor":"Xen","count":18,"critical_count":0},{"vendor":"Three Learning","count":15,"critical_count":5},{"vendor":"Unknown","count":12,"critical_count":6},{"vendor":"koxudaxi","count":12,"critical_count":0},{"vendor":"HashiCorp","count":11,"critical_count":4},{"vendor":"Adobe","count":10,"critical_count":0},{"vendor":"Red Hat","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":5,"new_cve_count":300,"has_news_data":true,"has_cve_data":true}