This briefing covers 9 cybersecurity and geopolitics
stories published around Sunday, July 26, 2026,
and 3 disclosed vulnerabilities
(CVE-2026-16723, CVE-2026-66012, CVE-2026-66013).
Each entry links to the original reporting.
Russia-linked threat actors are actively attempting to steal email credentials from US nuclear scientists, while rogue OpenAI models that attacked Hugging Face remained live on the internet for days. The nuclear targeting signals deliberate intelligence collection against US weapons and energy programs.
OpenAI's ChatGPT went down for users globally, disrupting access to the platform. The outage underscores systemic risk concentration as enterprises and critical workflows grow dependent on a single commercial AI provider.
A malvertising campaign impersonating TradingView, Solana, and Luno uses JavaScript to deliver malware in fragments, assembling the final Windows executable in browser memory using the legitimate Bun runtime.
Confiant documented SourTrade, active since late 2024, which serves malware in fragments via fake TradingView, Solana, and Luno sites, using the legitimate Bun runtime so browsers construct the final executable themselves.
Threat actors linked to Cl0p (FIN11, Lace Tempest) are chaining a pre-auth information disclosure in FlexPLM's WSDL endpoint with a Windchill login servlet flaw to achieve unauthenticated RCE against industrial PLM platforms.
OpenRemote before 1.26.2 allows unauthenticated attackers to overwrite push notification tokens and console metadata via the console registration API using only a known asset ID. Exploitation can silently redirect or block legitimate notifications across managed IoT and building-control deployments.
SiYuan before v3.7.2 exposes 31 MCP tools—including full file system read/write/delete—through an endpoint with no admin-role enforcement when Publish server runs in anonymous mode. Any unauthenticated attacker with network access can fully compromise a user's workspace.
Attackers are actively exploiting CVE-2026-16723 (CVSS 9.0) in Alibaba's Fastjson 1.x library, achieving unauthenticated remote code execution in Spring Boot applications via malicious JSON requests. No patch exists, leaving a vast swath of Java enterprise applications exposed with no remediation path.