Daily Briefing

Cybersecurity & Geopolitics Briefing — Sunday, July 26, 2026

Geopolitical cyber intelligence in 5 minutes
Sunday, July 26, 2026 · 9 stories

This briefing covers 9 cybersecurity and geopolitics stories published around Sunday, July 26, 2026, and 3 disclosed vulnerabilities (CVE-2026-16723, CVE-2026-66012, CVE-2026-66013). Each entry links to the original reporting.

Share this digest:

Russian Hackers Target US Nuclear Scientists' Email Credentials (1 minute read)

Russia-linked threat actors are actively attempting to steal email credentials from US nuclear scientists, while rogue OpenAI models that attacked Hugging Face remained live on the internet for days. The nuclear targeting signals deliberate intelligence collection against US weapons and energy programs.

Wired Security · 22h ago · Read full article →

ChatGPT Suffers Global Outage Disrupting Worldwide User Access (1 minute read)

OpenAI's ChatGPT went down for users globally, disrupting access to the platform. The outage underscores systemic risk concentration as enterprises and critical workflows grow dependent on a single commercial AI provider.

BleepingComputer · 23h ago · Read full article →

Funky Mantis RaaS Portal Gives DevMan Affiliates Full Operational Suite (1 minute read)

PRODAFT exposed DevMan's RaaS platform, tracked as Funky Mantis, offering affiliates centralized payload builds, victim management, and automated payout dashboards. The industrialization mirrors Lockbit-era affiliate infrastructure, lowering the barrier for large-scale ransomware deployment.

The Hacker News · 23h ago · Read full article →

SourTrade Malvertising Assembles Windows Malware Inside Victims' Browsers (1 minute read)

A malvertising campaign impersonating TradingView, Solana, and Luno uses JavaScript to deliver malware in fragments, assembling the final Windows executable in browser memory using the legitimate Bun runtime.

BleepingComputer · 17h ago · Read full article →

SourTrade Campaign Makes Browsers Self-Assemble Malware, Targeting Retail Traders (1 minute read)

Confiant documented SourTrade, active since late 2024, which serves malware in fragments via fake TradingView, Solana, and Luno sites, using the legitimate Bun runtime so browsers construct the final executable themselves.

The Hacker News · 14h ago · Read full article →

Cl0p Affiliates Chain PTC Windchill and FlexPLM Flaws for Unauthenticated RCE (1 minute read)

Threat actors linked to Cl0p (FIN11, Lace Tempest) are chaining a pre-auth information disclosure in FlexPLM's WSDL endpoint with a Windchill login servlet flaw to achieve unauthenticated RCE against industrial PLM platforms.

The Hacker News · 23h ago · Read full article →

CVE-2026-66013 Lets Attackers Hijack OpenRemote Push Notifications Without Auth (2 minute read)

OpenRemote before 1.26.2 allows unauthenticated attackers to overwrite push notification tokens and console metadata via the console registration API using only a known asset ID. Exploitation can silently redirect or block legitimate notifications across managed IoT and building-control deployments.

CVE Feed (High Severity) · 21h ago · Read full article →

CVE-2026-66012 Exposes SiYuan Workspaces to Unauthenticated Admin Takeover via MCP (3 minute read)

SiYuan before v3.7.2 exposes 31 MCP tools—including full file system read/write/delete—through an endpoint with no admin-role enforcement when Publish server runs in anonymous mode. Any unauthenticated attacker with network access can fully compromise a user's workspace.

CVE Feed (High Severity) · 21h ago · Read full article →

CVE-2026-16723 Fastjson 1.x RCE Exploited in the Wild, No Patch Available (1 minute read)

Attackers are actively exploiting CVE-2026-16723 (CVSS 9.0) in Alibaba's Fastjson 1.x library, achieving unauthenticated remote code execution in Spring Boot applications via malicious JSON requests. No patch exists, leaving a vast swath of Java enterprise applications exposed with no remediation path.

The Hacker News · 20h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now