Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware
A blow against one of the world’s most dangerous phishing groups
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
Swiss train maker tells ransomware crooks to get off at the next stop
Europol-led action against nihilistic violent extremist network “The Com”
Illinois Man Sentenced to Over Six Years in Prison for Identity Theft and Wire Fraud
Malware
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
Hacking
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
5-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533
Smashing the ServiceNow Sandbox – Pre Authentication RCE
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
OpenAI and Hugging Face partner to address security incident during model evaluation
The Vulnerability That Turned Adobe’s 300M-Install Extension Into a Full WhatsApp Takeover
CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
American Hackers-for-Hire Proposal Sparks Heavy Criticism
Intelligence and Information Warfare
Brochure Cybersecurity advisory Russian state actors are compromising IP cameras
UAC-0145 Primary Compromise Vectors as of July 2026
Inside Russia’s Camera-Hacking Espionage Campaign
Blog JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458
Cybersecurity
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Identity Attacks Overtake Exploits as Top Ransomware Cause
LG to Ban Residential Proxies from Smart TV Apps
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber
Google hit with $1 billion EU fine, in ‘constructive’ talks to avoid more penalties
Is Patching Dead? Vulnerability Management in the Post-Mythos Era
How AI guardrails are impeding the work of offensive cybersecurity researchers
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
