This briefing covers 20 cybersecurity and geopolitics
stories published around Thursday, July 30, 2026,
including activity involving FSB, Russia,
and 3 disclosed vulnerabilities
(CVE-2026-16526, CVE-2026-20316, CVE-2026-67248).
Each entry links to the original reporting.
Void Blizzard is exploiting an unpatched Microsoft Exchange OWA vulnerability to deploy the OWAReaper backdoor, maintaining persistent mailbox access across credential resets. The technique survives standard incident response, making eviction significantly harder for targeted organizations.
Amazon threat intelligence linked a minor npm package breach to the same North Korean group that later compromised the axios library, revealing it as a deliberate dry run. The pattern confirms Pyongyang is systematically probing open-source ecosystems before executing high-visibility supply-chain attacks.
Beginning July 22, 2026, Void Blizzard exploited a Microsoft OWA vulnerability to target U.S. and European government, telecom, finance, hospitality, and aerospace entities, persisting through credential rotation. The cross-sector scope signals intelligence collection at scale, not opportunistic access.
New research demonstrates that security scanners integrated into CI/CD pipelines can themselves be compromised to serve as footholds for downstream supply chain attacks. Defenders who trust scanner output as a security baseline now face a systemic blind spot.
A coordinated cyberattack disrupted more than 30 Minnesota water facilities, with Iran-linked CyberAv3ngers suspected though officials have not formally attributed. CyberAv3ngers previously hit U.S.
Angola's largest telco, Unitel, suffered a cyberattack disrupting voice, mobile data, and internet for millions of users nationwide on the eve of its landmark stock market listing. The timing raises questions about targeted sabotage of a high-profile economic milestone.
Russia's FSB formally charged Pavel Durov for allegedly hosting terrorist channels, chats, and bots in violation of Russian law. The move is a direct pressure campaign to force Telegram content compliance, or justify its effective exclusion from Russian-occupied information space.
Moscow is pursuing an international arrest warrant for Pavel Durov, alleging Telegram enabled Ukrainian intelligence to organize attacks and conduct espionage inside Russia. The escalation attempts to internationalize Russia's pressure on Telegram after domestic legal charges proved insufficient.
Georgia's ruling Georgian Dream party is dismantling independent courts, civil society, and opposition structures to consolidate one-party rule and deepen Russian influence. Without targeted Western sanctions, the EU's eastern neighborhood loses a democratic anchor and Russia gains a compliant corridor.
A hack of OpenAI's systems signals that technical controls on frontier AI models are insufficient to prevent adversary access or theft. Foreign Policy argues governments must abandon containment fantasies and shift resources to resilience and defensive AI policy.
Five years after warnings, Mexico's Guardia Nacional has fully locked in military dominance over civilian policing, accelerated by Trump administration pressure and a new presidential administration. The militarization trap is now structural, with civilian oversight mechanisms effectively dismantled.
The US government banned imports of foreign-made humanoid robots, explicitly targeting China over cybersecurity and national security concerns around advanced robotics. The move extends the US-China technology decoupling into physical AI systems capable of operating in sensitive environments.
Flying Eagle is a premium malware-as-a-service toolkit circulating in China, enabling multiple threat actors to build mobile infostealers that exfiltrate banking credentials. A full-service builder model lowers the technical barrier and accelerates distribution beyond any single group's operational reach.
Threat actors ran a nine-year fraud operation cloning Russian fertilizer, petrochemical, and major company websites to steal advance payments from international buyers, per F6.
CISA added CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center, to its KEV catalog after confirmed zero-day exploitation allowing unauthenticated remote login. A firewall management platform compromised at the authentication layer exposes full network visibility to attackers.
CISA's KEV catalog addition of CVE-2026-20316 mandates remediation under BOD 26-04; the flaw allows unauthenticated remote access to Cisco Firewall Management Center via a built-in low-privileged account.
CVE-2026-16526 (CVSS 8.8) in PCP's linux_sockets PMDA exposes an unsecured internal connection, enabling local attackers with initial code execution to gain full root access. Any system running PCP for performance monitoring is a lateral-movement stepping stone.
CVE-2026-67248 is a stack-based buffer overflow in ASUSTOR ADM's File Explorer, allowing authenticated attackers to crash the CGI process with potential for further exploitation. NAS devices are high-value targets for ransomware staging and data exfiltration.
Cisco confirmed CVE-2026-20316, a high-severity static credential vulnerability in Secure Firewall Management Center, is actively exploited in zero-day attacks granting unauthorized device access. Compromised FMC instances give attackers policy-level control over enterprise firewall infrastructure.
CVE-2026-20316 in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to log into affected devices via static credentials, and is actively exploited in the wild. Full FMC access means adversaries can rewrite firewall policy across managed device fleets.