Daily Briefing

Cybersecurity & Geopolitics Briefing — Tuesday, July 28, 2026

Geopolitical cyber intelligence in 5 minutes
Tuesday, July 28, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Tuesday, July 28, 2026, and 3 disclosed vulnerabilities (CVE-2025-68686, CVE-2026-16812, CVE-2026-53264). Each entry links to the original reporting.

Share this digest:

China-Linked Group Uses Cruciferra Crypter With BYOVD to Target Indian Finance (1 minute read)

A China-linked cybercrime cluster is deploying Cruciferra, a crypter using Bring Your Own Vulnerable Driver and Process Ghosting, via income-tax phishing lures against Indian taxpayers and corporate finance teams, per Proofpoint.

The Hacker News · 22h ago · Read full article →

Telegram Phishing Campaign Targets Exiled Belarusian Activist and Post-Soviet Users (1 minute read)

A highly personalized Telegram-based phishing operation attempted to hijack accounts belonging to an exiled Belarusian activist and users in Russia and Kazakhstan. The targeting pattern points to a state-aligned actor conducting transnational repression and monitoring of diaspora and civil-society networks.

The Record · 17h ago · Read full article →

Unknown Actor Deploys Autonomous AI Agent Against Thailand Finance Ministry (1 minute read)

Unattributed hackers used an autonomous AI agent to conduct cyber-espionage against Thailand's Ministry of Finance. The use of agentic AI marks an operational shift in threat actor tradecraft, lowering the skill floor for sustained espionage campaigns.

The Record · 21h ago · Read full article →

Trump Halts New Iran Strikes After Two-Week Daily Bombardment Campaign (2 minute read)

President Trump ordered a pause in U.S. military strikes against Iran on Friday, ending a nearly two-week streak of daily attacks, per two sources. The halt coincides with reported diplomatic contacts, suggesting a coercion-to-negotiation pivot with significant escalation risk if talks stall.

Just Security · 21h ago · Read full article →

Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown (1 minute read)

Dysphoria botnet, tracked by CNCERT and XLab, shifted to blockchain-based name services and infected-device relays following a March 2026 law-enforcement disruption of JackSkid infrastructure.

The Hacker News · 16h ago · Read full article →

Malware Forces South Carolina and Georgia AnMed Health to Shutter Offices (1 minute read)

AnMed Health closed offices across South Carolina and Georgia after malware disrupted its networks, with scope still undetermined. Healthcare infrastructure attacks continue to translate directly into patient care disruptions, reinforcing the sector's status as a high-impact soft target.

The Record · 16h ago · Read full article →

Orbán's Weakening Reshapes Serbia's Geopolitical Alignment Away From Moscow (3 minute read)

Serbia is recalibrating its foreign policy posture as Hungary's Viktor Orbán loses regional influence, eroding a key buffer between Belgrade and Western institutions.

War on the Rocks · 2h ago · Read full article →

Senator Wyden Demands CISA Purge Outdated Federal Agency VPNs (1 minute read)

Intelligence Committee member Ron Wyden is pressing CISA, OMB, and NIST to lead a government-wide audit and removal of obsolete VPN software from U.S. federal networks.

The Record · 12h ago · Read full article →

Israel's Cognyte Sells Mobile IMSI-Catcher Vans to U.S. States (2 minute read)

Cognyte's FalcoNet cell-site simulator, deployed in vehicles, backpacks, and helicopters, was sold to Texas under a state contract. Mass collection of bystander device data by a foreign surveillance vendor raises serious Fourth Amendment and counterintelligence exposure questions.

Schneier on Security · 22h ago · Read full article →

Autocrats Signal Fear of Civil Society and Anti-Censorship Tools Over Sanctions (1 minute read)

Research finds authoritarian regimes respond more aggressively to independent media support and anti-censorship technology than to military strikes or sanctions. Western policy that prioritizes kinetic and economic pressure over information-space tools is misaligned with what adversaries actually fear.

Just Security · 20h ago · Read full article →

Trump and Netanyahu Split Over Iran War Strategy at High-Stakes Meeting (1 minute read)

Trump and Netanyahu enter talks divided on Iran policy, with the U.S. pursuing diplomacy while Israel favors military action. The rift exposes a fracture in the Western coalition's Iran posture at a moment when Tehran is calculating escalation risk.

Foreign Policy · 12h ago · Read full article →

U.S. Sanctions Devastate Iran's Economy but Fail to Shift Strategic Behavior (1 minute read)

Maximum-pressure sanctions have severely damaged Iran's economy without producing measurable changes in Tehran's nuclear or regional proxy strategy. The disconnect undermines the coercive theory of economic warfare and raises questions about escalation options as U.S.-Iran military strikes continue.

Foreign Policy · 3h ago · Read full article →

Anubis Ransomware Group Breaches Coca-Cola via Fairlife Attack (1 minute read)

The Anubis cybercrime group executed a ransomware attack against Fairlife, leading Coca-Cola to confirm a data breach, with Anubis threatening to leak stolen data. A successful hit on a Fortune 500 subsidiary demonstrates that ransomware actors are escalating pressure through brand-name reputational leverage.

SecurityWeek · 22h ago · Read full article →

CISA Flags CVE-2025-68686 Fortinet FortiOS Sensitive Data Exposure (3 minute read)

Fortinet FortiOS carries CVE-2025-68686, allowing remote unauthenticated attackers to bypass symbolic-link persistence patches via crafted HTTP requests on already-compromised systems. CISA's KEV listing confirms active exploitation, pressing federal agencies toward immediate mitigation under BOD 26-04.

CISA KEV · 1d ago · Read full article →

AI-Assisted CVE-2026-53264 Linux Kernel Race Turned Into Root Exploit (1 minute read)

STAR Labs researcher Lee Jia Jie used AI to discover and weaponize CVE-2026-53264, a CVSS 7.8 use-after-free race in Linux's traffic-control subsystem, achieving local privilege escalation to root on CentOS Stream 9.

The Hacker News · 1h ago · Read full article →

CISA Adds CVE-2026-16812 Arista VeloCloud OS Injection to KEV Catalog (3 minute read)

Arista VeloCloud Orchestrator On-Prem carries CVE-2026-16812, an OS command injection flaw enabling remote attackers to compromise orchestrator confidentiality, integrity, and availability.

CISA KEV · 1d ago · Read full article →

CVE-2026-16812 CVSS 10.0 Arista VeloCloud Orchestrator Exploited in the Wild (1 minute read)

Attackers are actively exploiting CVE-2026-16812, a maximum-severity OS command injection flaw in on-premises Arista VeloCloud Orchestrator enabling arbitrary code execution. Network edge orchestration platforms are high-value pivot points; active exploitation before broad patching signals targeted pre-positioning.

The Hacker News · 4h ago · Read full article →

Unknown Hackers Exploit FastJson Zero-Day RCE Against U.S. Firms (1 minute read)

Attackers are actively exploiting an unauthenticated remote code execution zero-day in the FastJson Java library targeting U.S. companies. A widely embedded open-source library hit with a zero-day creates broad, difficult-to-inventory exposure across enterprise Java environments.

BleepingComputer · 9h ago · Read full article →

Arista Patches CVE-2026-16812 Max-Severity VeloCloud Zero-Day Under Active Attack (1 minute read)

Arista released patches for CVE-2026-16812, a CVSS 10.0 command injection zero-day in on-premises VeloCloud Orchestrator already being exploited. Organizations running on-prem SD-WAN orchestration without the patch remain exposed to full remote compromise of network control planes.

BleepingComputer · 10h ago · Read full article →

Certighost PoC Exploit Released Enabling Authenticated Windows Domain Takeover (1 minute read)

A public proof-of-concept for Certighost, an Active Directory Certificate Services vulnerability, allows authenticated attackers to compromise an entire Windows domain. Public PoC release dramatically compresses the exploitation window, prioritizing patching for any AD CS deployment.

BleepingComputer · 12h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now