Morning Brief

Friday, July 31, 2026 · generated 2026-07-31 16:24 UTC · ~6 min read

Patch today
56
HashiCorp
1 critical
37
WordPress
1 critical
25
Unknown
3 critical
23
IBM
5 critical
19
Red Hat
16
Apache
6
Microsoft
1 critical
6
SGLang
6
cloudreve
5
MZ Automation GmbH

Top developments

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions…

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz…

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports

The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after…

Google Earth’s New AI Lets Anyone Fabricate Completely Bullshit Satellite Images

On Thursday, Google introduced a new AI feature into Google Earth which lets anyone fabricate all sorts of misleading or straight up inaccurate satellite imagery, from making it look like a specific place has suffered a…

Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now

JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077 . This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects…

North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials

A North Korean-linked cyber campaign is using fake macOS update screens to trick victims into installing malware. The operation targets cryptocurrency wallets, browser data, and developer credentials, turning a routine…

BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations

BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The malware gives intruders a way to…

ShutterGap Exposes Millions of AWS Resources Between Cloud Security Scans

Cloud security teams often utilize Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tools to identify risky configurations. However, new research from Aryon Security…

North Korean hackers behind major open-source supply chain attacks, Amazon says

A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.

Vulnerability watch

CVE-2026-66803 Microsoft · Azure Cosmos DB CWE-284 CRITICAL 10.0 · EPSS 0%

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

CVE-2026-18452 Rich Source · DMS+ (Non-Mobile) CWE-798 CRITICAL 10.0 · EPSS 0%

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

CVE-2026-13435 IBM · Langflow OSS CWE-94 CRITICAL 9.9 · EPSS 0%

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

CVE-2026-12946 IBM · Langflow OSS CWE-94 CRITICAL 9.9 · EPSS 0%

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

CVE-2026-28323 SolarWinds · Web Help Desk CWE-287 CRITICAL 9.8 · EPSS 0%

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

CVE-2026-4978 UMAI Vision · Traffic Analysis System CWE-89 CRITICAL 9.8 · EPSS 0%

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.

CVE-2026-12940 IBM · Langflow OSS CWE-78 CRITICAL 9.8 · EPSS 0%

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.…

CVE-2026-12118 IBM · webMethods Integration (on prem) CWE-502 CRITICAL 9.8 · EPSS 0%

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

CVE-2026-12943 IBM · HMC V10.3.1050.0 CWE-78 CRITICAL 9.8 · EPSS 0%

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges…

CVE-2026-67208 somta · Juggle CWE-306 CRITICAL 9.8 · EPSS 1%

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attack…

Full CVE Feed →

Worth reading

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable…

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security…

ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware ESXi. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →