Clear Infosec weekly Threat Intelligence Bulletin for July 29, 2026. Curated cyber security news, threats, and guidance with links to the original sources.
Cyber Security News
- Russian Hackers Exploit Zimbra Zero-Day Against US Ukraine Targets A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the…
- Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken…
- Attackers Are Learning to Live Off the AI Toolchain Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal act…
- Thousands of Data Center Controllers Open to Takeover A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note…
- Confused Deputy Flaws Persist in Google Cloud Microsoft Azure This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls…
Best Practices
- Ransomware groups are hammering your vulnerable VPNs Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy th…
- Microsoft’s 3-day patching directive comes with added operational risk Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over…
- Critical Zimbra security update fixes 9 vulnerabilities Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow at…
- Cisco’s new AI model tells code reviewers where to look for vulnerabilities Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable…
New Threats and Vulnerabilities
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-su…
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, fo…
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure desig…
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, whi…
Patch Management
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsofts Servers A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux…
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researc…
- Fake Notepad++ Plugin Delivers MATCHBOILV2 in UAC-0099 Attacks The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notep…
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, whi…
AI and Security
- AI has changed data architecture but storage hasnt caught up Your GPU dashboard says 70% utilization. On paper, the cluster is busy. In practice, a large chunk of that time is spent with your $40,000 accelerators sitting…
- How AI drove Shopify back to clean code E-commerce platform Shopify wants to make reading source code a thing again. And it has an unlikely ally for its back-to-the-roots approach: AI agents. The com…
- OpenAI admits it was the source of the agent swarm that attacked Hugging Face OpenAI has admitted that it was the operator of the autonomous agents that attacked model-mart Hugging Face last week, and that they did so after a research pr…








