📡 Tech & Security Digest — 2026-07-31
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- Anthropic is finding bugs faster than Microsoft can fix them — Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them. …
BleepingComputer
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access — The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in ema…
- Cisco warns of FMC static credential flaw exploited in zero-day attacks — Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively…
- Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests — One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real s…
- ShinyHunters claims Brinks Home breach, threatens to leak stolen data — Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [….
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach — In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recen…
- JetBrains warns of critical TeamCity remote code execution flaw — JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code e…
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers — Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hacke…
Hacker News
- Investigating three real-world incidents in our cybersecurity evaluations (176 pts)
- Hacker Public Radio (152 pts)
The Hacker News
- Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts — South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers u…
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerabi…
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Mana…
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild….
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boo…
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories — A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or…
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Ma…
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and Open…
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach — JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluatio…
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database — A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write ac…