12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS
THN · BleepingComputer · Krebs · Dark Reading · SANS
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 28, 2026.
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
— Bleeping Computer
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard M… -
Data breach at medical billing firm MCBS affects 1.26 million people
— Bleeping Computer
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive informat… -
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
— The Hacker News
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical secur… -
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
— The Hacker News
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The fla… -
AutoIT Payload Injector , (Tue, Jul 28th)
— SANS ISC
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and po… -
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
— The Hacker News
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation har… -
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
— The Hacker News
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in… -
ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
AI Agent Drives Espionage Attack on Thai Ministry of Finance
— Dark Reading
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finan… -
Hackers target US firms in FastJson RCE zero-day attacks
— Bleeping Computer
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user intera… -
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
— Bleeping Computer
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being active… -
Agentic Browsers Rewind Web Security by 20 years
— Dark Reading
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin reque…
Generated by HiveNet.ai Threat Intelligence Platform · July 28, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC