This briefing covers 20 cybersecurity and geopolitics
stories published around Tuesday, July 28, 2026,
and 3 disclosed vulnerabilities
(CVE-2025-68686, CVE-2026-16812, CVE-2026-53264).
Each entry links to the original reporting.
A China-linked cybercrime cluster is deploying Cruciferra, a crypter using Bring Your Own Vulnerable Driver and Process Ghosting, via income-tax phishing lures against Indian taxpayers and corporate finance teams, per Proofpoint.
A highly personalized Telegram-based phishing operation attempted to hijack accounts belonging to an exiled Belarusian activist and users in Russia and Kazakhstan. The targeting pattern points to a state-aligned actor conducting transnational repression and monitoring of diaspora and civil-society networks.
Unattributed hackers used an autonomous AI agent to conduct cyber-espionage against Thailand's Ministry of Finance. The use of agentic AI marks an operational shift in threat actor tradecraft, lowering the skill floor for sustained espionage campaigns.
President Trump ordered a pause in U.S. military strikes against Iran on Friday, ending a nearly two-week streak of daily attacks, per two sources. The halt coincides with reported diplomatic contacts, suggesting a coercion-to-negotiation pivot with significant escalation risk if talks stall.
Dysphoria botnet, tracked by CNCERT and XLab, shifted to blockchain-based name services and infected-device relays following a March 2026 law-enforcement disruption of JackSkid infrastructure.
AnMed Health closed offices across South Carolina and Georgia after malware disrupted its networks, with scope still undetermined. Healthcare infrastructure attacks continue to translate directly into patient care disruptions, reinforcing the sector's status as a high-impact soft target.
Serbia is recalibrating its foreign policy posture as Hungary's Viktor Orbán loses regional influence, eroding a key buffer between Belgrade and Western institutions.
Intelligence Committee member Ron Wyden is pressing CISA, OMB, and NIST to lead a government-wide audit and removal of obsolete VPN software from U.S. federal networks.
Cognyte's FalcoNet cell-site simulator, deployed in vehicles, backpacks, and helicopters, was sold to Texas under a state contract. Mass collection of bystander device data by a foreign surveillance vendor raises serious Fourth Amendment and counterintelligence exposure questions.
Research finds authoritarian regimes respond more aggressively to independent media support and anti-censorship technology than to military strikes or sanctions. Western policy that prioritizes kinetic and economic pressure over information-space tools is misaligned with what adversaries actually fear.
Trump and Netanyahu enter talks divided on Iran policy, with the U.S. pursuing diplomacy while Israel favors military action. The rift exposes a fracture in the Western coalition's Iran posture at a moment when Tehran is calculating escalation risk.
Maximum-pressure sanctions have severely damaged Iran's economy without producing measurable changes in Tehran's nuclear or regional proxy strategy. The disconnect undermines the coercive theory of economic warfare and raises questions about escalation options as U.S.-Iran military strikes continue.
The Anubis cybercrime group executed a ransomware attack against Fairlife, leading Coca-Cola to confirm a data breach, with Anubis threatening to leak stolen data. A successful hit on a Fortune 500 subsidiary demonstrates that ransomware actors are escalating pressure through brand-name reputational leverage.
Fortinet FortiOS carries CVE-2025-68686, allowing remote unauthenticated attackers to bypass symbolic-link persistence patches via crafted HTTP requests on already-compromised systems. CISA's KEV listing confirms active exploitation, pressing federal agencies toward immediate mitigation under BOD 26-04.
STAR Labs researcher Lee Jia Jie used AI to discover and weaponize CVE-2026-53264, a CVSS 7.8 use-after-free race in Linux's traffic-control subsystem, achieving local privilege escalation to root on CentOS Stream 9.
Attackers are actively exploiting an unauthenticated remote code execution zero-day in the FastJson Java library targeting U.S. companies. A widely embedded open-source library hit with a zero-day creates broad, difficult-to-inventory exposure across enterprise Java environments.
Arista released patches for CVE-2026-16812, a CVSS 10.0 command injection zero-day in on-premises VeloCloud Orchestrator already being exploited. Organizations running on-prem SD-WAN orchestration without the patch remain exposed to full remote compromise of network control planes.
A public proof-of-concept for Certighost, an Active Directory Certificate Services vulnerability, allows authenticated attackers to compromise an entire Windows domain. Public PoC release dramatically compresses the exploitation window, prioritizing patching for any AD CS deployment.