{"date_iso":"2026-07-30","date_human":"Thursday, July 30, 2026","generated_utc":"2026-07-30 13:00 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents","link":"https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html","reason":"Microsoft","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-BgxoTGLqXYzQh4HW0TUm-hbX0ApFizzFtFkKe5mb3fKS_yn6Zzpj_Uvivxi7VCwEUOuJx3Bg1XHpHWq9tbZh5xBrAHT4gBG2DYyqvFkVKmWIRiF_zCpXIG5bTs7HfsV1pjM2EsTm-e7WttN-iB57p0n4ki2Vs7vXyB6rTF9mSqlwPu3h7KHocg0mWcI/s1600/copilot-word.jpg","description":"Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. H\u00e5kon M\u00e5l\u00f8y disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. M\u00e5l\u00f8y's","related":[{"title":"Hidden prompt turns Microsoft Copilot into an AI worm","link":"https://www.malwarebytes.com/blog/ai/2026/07/hidden-microsoft-copilot-ai-worm","source":"Malwarebytes Labs","date_rel":"1m ago"},{"title":"Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages","link":"https://www.infosecurity-magazine.com/news/teams-phishing-abused-legit/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Russian spies take their half-click email attack from Zimbra to Outlook","link":"https://www.theregister.com/security/2026/07/30/russian-spies-take-their-half-click-email-attack-from-zimbra-to-outlook/5281033","source":"The Register Security","date_rel":"2h ago"},{"title":"Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT","link":"https://cybersecuritynews.com/fake-flash-player-installer/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"A Two-Minute Microsoft Teams Call Could End With Your Network Encrypted With Ransomware","link":"https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation","link":"https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html","source":"The Hacker News","date_rel":"5h ago"}]},{"title":"Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data","link":"https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-20316"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFSDmsE6q7010reBwpOwS1ESkJSxlBlgRBbtjEVAdeClQFAkRfpriRQWUpL0Br8xnFdF1mctv4Ttj1Nv77MMIKm9qlNehPtTLYzOQwcZAWR4Vw1HzjAvItevYjwQkUo_2JNRluc2_OeJ3vOZ-P8meai9NLLWBvothfh7GDqoOpMPmKpOO-hjAeY-Pxa-BV/s1600/cisco.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log","related":[{"title":"Cisco security advisory (AV26-757)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-757","source":"CCCS Alerts & Advisories","date_rel":"14m ago"},{"title":"Cisco warns of FMC static credential flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"15h ago"}]},{"title":"The Network Has Become the Control Plane for AI Security","link":"https://thehackernews.com/2026/07/the-network-has-become-control-plane.html","reason":"Teams","category":"News","sources":["Dark Reading","Recorded Future Intelligence","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCMiEYFcCrvL7s-o_ZApEbF6gP4J5FpWseBSQN2iP5bBIXP51mVR8QDnUmxDHBrMr0ta6ucsouVsVnWg8mGPeRvwkx09PCddi0pWLYzOpeA7NnrKUaeVhypXKK9rBJSfminUSBH9cz4YTelqUFMU-VZU2G-mkKFhb1pMQsGcAqtuT4btXzbbgb4pD1Mdfi/s1600/checkpoint-main.jpg","description":"Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls","related":[{"title":"Dealing with AI-Generated Extortion","link":"https://www.recordedfuture.com/blog/ai-generated-extortion","source":"Recorded Future Intelligence","date_rel":"13h ago"},{"title":"Hugging Face Hack: Lessons for Cyber Defenders","link":"https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders","source":"Dark Reading","date_rel":"19h ago"}]},{"title":"North Korean hackers behind major open-source supply chain attacks, Amazon says","link":"https://therecord.media/north-korea-hackers-amazon-malware","reason":"Amazon","category":"News","sources":["CyberScoop","The Hacker News","The Record"],"coverage":3,"cve_ids":[],"summary":"A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.","source":"The Record","date_rel":"just now","thumbnail":"http://cms.therecord.media/uploads/Javascript_ebfda374da.jpg","description":"","related":[{"title":"Amazon Links Debug and Chalk npm Hijack to North Korea\u2019s Sapphire Sleet","link":"https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"A little-known npm package was North Korea\u2019s warm-up act for the axios hack","link":"https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/","source":"CyberScoop","date_rel":"15h ago"}]},{"title":"Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)","link":"https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310","reason":"Broadcom","category":"Research","sources":["Rapid7 Blog","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-59309","CVE-2026-59310"],"summary":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable\u2026","source":"Rapid7 Blog","date_rel":"2h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server. CVE CVSSv3.1 Description Summary CVE-2026-59309 9.8 (Critical) An authentication bypass vulnerability in the VMware Directory Service of vCenter that\u2026","related":[{"title":"Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape","link":"https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html","source":"The Hacker News","date_rel":"21h ago"}]},{"title":"Wiz\u2019s First 6 Months as Part of Google","link":"https://www.wiz.io/blog/6-months-google","reason":"Google","category":"Research","sources":["Infosecurity Magazine","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"Fast gets even faster: redefining security for the AI era and doubling down on our multicloud commit","source":"Wiz Research","date_rel":"22h ago","thumbnail":"https://www.datocms-assets.com/75231/1742297622-wiz-google.png","description":"","related":[{"title":"Google Releases Patches for 370 Vulnerabilities in Chrome 151","link":"https://www.infosecurity-magazine.com/news/google-patches-370-vulnerabilities/","source":"Infosecurity Magazine","date_rel":"3h ago"}]},{"title":"MZ Automation lib60870","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11","reason":"CVE-2026-61893","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":["CVE-2026-61893","CVE-2026-63033"],"summary":"View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033) CVSS Vendor Equipment Vulnerabilities v3 6.5 MZ Automation GmbH MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Energy, Water and Wastewater, Critical Manufacturing, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-61893 A crafted IEC 60870-5-104 I-frame with TypeID 104\u2026","related":[{"title":"MZ Automation lib60870","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05","reason":"Rockwell","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 /\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module are affected: ControlLogix 5580 >=V36|<=V37 (CVE-2026-9636) CompactLogix 5380 >=V36|<=V37 (CVE-2026-9636) GuardLogix 5580 >=V36|<=V37 (CVE-2026-9636) Compact GuardLogix 5380 >=V36|<=V37 (CVE-2026-9636) 1756-EN4TR V6.001 (CVE-2026-9636) 1756-EN4TR V7.001 (CVE-2026-9636) CVSS Vendor Equipment Vulnerabilities v3 5.9 Rockwell Automation Rockwell Automation\u2026","related":[{"title":"Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"Schneider Electric IGSS","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","reason":"Scada","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could\u2026","related":[{"title":"Schneider Electric IGSS","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-04","source":"CISA ICS Advisories","date_rel":"1h ago"}]},{"title":"NASA Core Flight System (cFS) Health & Safety (HS) Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06","reason":"Application Safety Health","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application\u2026","source":"CISA Alerts & Advisories","date_rel":"1h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application <=v7.0.1 (CVE-2026-18064) CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United\u2026","related":[{"title":"NASA Core Flight System (cFS) Health & Safety (HS) Application","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-06","source":"CISA ICS Advisories","date_rel":"1h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-54735","vendor":"prebid","product":"prebid-server","severity":"CRITICAL","score":10.0,"description":"Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without prope\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":0.0035,"url":"https://cve.blackmesa.ca/?q=CVE-2026-54735"},{"id":"CVE-2026-16326","vendor":"HashiCorp","product":"Tooling","severity":"CRITICAL","score":10.0,"description":"In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (C\u2026","cwe":"CWE-488","kev":false,"kev_action":"","kev_due":"","epss":0.003,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16326"},{"id":"CVE-2026-67429","vendor":"flytohub","product":"flyto-core","severity":"CRITICAL","score":10.0,"description":"Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR c\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":0.0049,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67429"},{"id":"CVE-2026-48449","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is ch\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":0.0054,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48449"},{"id":"CVE-2026-54680","vendor":"Kubernetes","product":"logging-operator","severity":"CRITICAL","score":9.9,"description":"Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_tr\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-54680"},{"id":"CVE-2026-58046","vendor":"WebPros","product":"Plesk","severity":"CRITICAL","score":9.9,"description":"Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0031,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58046"},{"id":"CVE-2026-60112","vendor":"NASA-AMMOS","product":"AIT-GUI","severity":"CRITICAL","score":9.8,"description":"AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0041,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60112"},{"id":"CVE-2026-60113","vendor":"NASA-AMMOS","product":"AIT-DSN","severity":"CRITICAL","score":9.8,"description":"AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0041,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60113"},{"id":"CVE-2026-67191","vendor":"Xlight","product":"Xlight FTP Server","severity":"CRITICAL","score":9.8,"description":"Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A l\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":0.0058,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67191"},{"id":"CVE-2026-41939","vendor":"Microsoft","product":"Care Everywhere Gateway","severity":"CRITICAL","score":9.8,"description":"Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials \u2026","cwe":"CWE-1392","kev":false,"kev_action":"","kev_due":"","epss":0.008,"url":"https://cve.blackmesa.ca/?q=CVE-2026-41939"}],"vendor_spikes":[{"vendor":"Google","count":370,"critical_count":42},{"vendor":"WordPress","count":43,"critical_count":2},{"vendor":"Unknown","count":21,"critical_count":6},{"vendor":"Phoenix Contact","count":20,"critical_count":8},{"vendor":"Apple","count":13,"critical_count":0},{"vendor":"GitLab","count":13,"critical_count":0},{"vendor":"balbooa.com","count":11,"critical_count":0},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"ASUSTOR Inc.","count":8,"critical_count":0},{"vendor":"netty","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":13,"new_cve_count":662,"has_news_data":true,"has_cve_data":true}