Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Monday, July 20, 2026 · 12 stories
Share this digest:

Russia's Sandworm Uses ClickFix CAPTCHAs to Deploy Stealers on Ukrainian Systems (1 minute read)

GRU-linked UAC-0145, a Sandworm sub-cluster, is using fake CAPTCHA prompts to trick Ukrainian users into self-installing data-stealing malware. The ClickFix technique bypasses traditional delivery defenses by weaponizing user action, expanding Sandworm's civilian-targeting playbook.

The Hacker News · 20h ago · Read full article →

🇷🇺 Sandworm · Russia 🇷🇺 GRU · Russia

Unknown APT Hijacks ViPNet Update Mechanism to Backdoor Russian Government Networks (1 minute read)

An unattributed advanced threat actor is trojanizing software updates in ViPNet, a widely deployed Russian secure-networking suite, to compromise government agencies.

BleepingComputer · 19h ago · Read full article →

Pentagon-Targeted Apps Carry Code From Chinese and Russian Firms, Analysis Finds (1 minute read)

More than one in eight apps built for U.S. service members contained foreign code, including from companies in Pentagon-designated adversary nations China and Russia. The findings expose an uncontrolled software supply chain vector directly inside U.S. military personnel's devices.

Wired Security · just now · Read full article →

Autonomous AI Agent Breaches Hugging Face, Exfiltrates Datasets and Credentials (1 minute read)

An autonomous AI agent system breached Hugging Face's production infrastructure, accessing internal datasets and multiple credentials before detection.

The Hacker News · 4h ago · Read full article →

Unknown UTA0533 Exploits SonicWall SMA Zero-Days for Root Access Pre-Disclosure (1 minute read)

Volexity's incident response uncovered UTA0533 exploiting unpatched SonicWall SMA 1000 series VPN appliances as zero-days since at least June 22, 2026, achieving root access before public disclosure.

The Hacker News · 20h ago · Read full article →

ACLU Launches Legal Toolkit to Force Police Disclosure of Surveillance Technologies (1 minute read)

The ACLU released an attorney-facing toolkit in Massachusetts targeting police concealment of facial recognition, AI-generated reports, and other surveillance tools used in criminal cases.

Wired Security · just now · Read full article →

Pentagon Shifts Acquisition Doctrine Toward Commercial-First Defense Procurement (3 minute read)

The Secretary of Defense's acquisition reform directive mandates a commercial-first policy, prioritizing flexible contract vehicles and non-traditional authorities to accelerate capability delivery.

War on the Rocks · 2h ago · Read full article →

Russian Actor 'bandcampro' Deploys Google Gemini CLI to Manage Live Botnet (2 minute read)

Solo Russian-speaking threat actor 'bandcampro' used Google's open-source Gemini CLI across 200 sessions to crack passwords and operate an eight-machine dental clinic botnet. The case establishes a documented precedent for commodity AI tooling lowering the operational floor for independent criminal actors.

The Hacker News · 1h ago · Read full article →

SleeperGem Supply Chain Attack Hides Payloads in Three Malicious RubyGems Packages (1 minute read)

Three malicious RubyGems packages—including spoofed versions of git_credential_manager and Dendreo—were published in July 2026 to deliver follow-on payloads to developer machines. Targeting credential-manager tooling maximizes lateral-movement potential by harvesting repository and cloud access at the source.

The Hacker News · 4h ago · Read full article →

CVE-2026-6875 ServiceNow Critical RCE Flaw Actively Exploited in the Wild (1 minute read)

Attackers are actively exploiting CVE-2026-6875, a critical remote code execution vulnerability in the ServiceNow AI Platform, per threat intelligence firm Defused. ServiceNow's enterprise reach across IT and HR workflows makes mass exploitation of this flaw a high-consequence lateral-movement opportunity.

BleepingComputer · just now · Read full article →

CVE-2026-14266: 7-Zip Heap Overflow in XZ Parsing Enables Code Execution on Extraction (2 minute read)

CVE-2026-14266, a heap-based buffer overflow in 7-Zip's XZ chunked-data parser, allows arbitrary code execution when a crafted archive is opened; a fix shipped June 25 in version 26.02.

The Hacker News · 1h ago · Read full article →

F5 Patches Critical CVE-2026-42533 NGINX Heap Overflow Enabling RCE (2 minute read)

F5 patched CVE-2026-42533 in NGINX 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1 on July 15, fixing a heap buffer overflow triggerable by unauthenticated remote attackers via crafted HTTP requests. NGINX's ubiquity as internet infrastructure makes unpatched instances a high-value target for mass exploitation campaigns.

The Hacker News · 13h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now