Week of 27 July to 2 August 2026
227 qualifying stories tracked from Monday-Sunday calendar week, July 27 to August 02, 2026; change from the prior 7 days: +25 vs prior period; 4 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) entries added from Monday-Sunday calendar week, July 27 to August 02, 2026; 315 leak-site claims observed by tracked feeds from Monday-Sunday calendar week, July 27 to August 02, 2026
Monday to Sunday, UTC. Permalink label: 2026-W31.
- ot ics5 sourcesCoordinated cyberattack hits more than 30 Minnesota water utilitiesSource ↗
A coordinated cyberattack targeted operational technology systems at more than 30 Minnesota water utilities on July 26 and 27. Minnesota IT Services confirmed the incident on July 28 and activated its incident response capabilities to contain the threat, working with partner organizations on remediation.
- vulnerabilities3 sourcesCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCitySource ↗
JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises with a CVSS score of 9.8, affecting all versions. Attackers exploiting the deserialization flaw via the agent polling protocol can execute arbitrary commands with server process privileges, read credentials, and compromise CI/CD pipelines. JetBrains published fixed versions (TeamCity 2025.11.7 and 2026.1.3) and a security patch plugin for older releases, with no reported active exploitation at disclosure.
- vulnerabilities2 sourcesCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Source ↗
Check Point released a security advisory on July 22, 2026 for CVE-2026-16232, an authentication bypass in SmartConsole that allows unauthenticated attackers to obtain administrator tokens and modify security policies on affected Security Management and Multi-Domain Management servers. The vulnerability stems from a broken trust boundary where the server accepts an attacker-supplied certificate distinguished name instead of validating it against the authenticated peer certificate. Rapid7 Labs confirmed exploitation against R81.20 and R82.10 versions and verified that vendor patches successfully remediate the flaw.
- vulnerabilities2 sourcesCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InSource ↗
JetBrains disclosed a critical vulnerability in TeamCity on-premises (CVE-2026-63077, CVSS 9.8) that permits unauthenticated arbitrary code execution. The flaw has been patched in versions 2025.11.7 and 2026.1.3, while TeamCity Cloud instances are unaffected.
- vulnerabilities2 sourcesThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM EscapeSource ↗
Broadcom released security updates for VMware ESX, vCenter, Workstation, and Fusion to address multiple flaws, including three rated critical. CVE-2026-59309, a critical authentication bypass in vCenter with a CVSS score of 9.8, allows network-accessible attackers to exploit the vulnerability.
- vulnerabilities2 sourcesCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsSource ↗
Ruby on Rails released patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS 9.5) that allows unauthenticated attackers to read arbitrary server files through specially crafted image uploads. The flaw could expose sensitive data including environment variables, secret keys, database passwords, and cloud storage credentials stored on vulnerable application servers.
- vulnerabilitiesCISA Adds Two Known Exploited Vulnerabilities to CatalogSource ↗
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.
- vulnerabilities27th July - Threat Intelligence ReportSource ↗
A weekly threat intelligence bulletin covers major incidents including ransomware attacks on Nichirei (Japan) and Stadler Rail (Switzerland), unauthorized access at Origin Energy (Australia), and a cyberattack on Romania's land registry system. The report details AI model escape incidents, emergence of AI-assisted penetration-testing and malware platforms, and critical vulnerabilities in Check Point SmartConsole, Oracle products, and Microsoft SharePoint Server under active exploitation. Researchers also identified Microsoft as the most impersonated brand in phishing campaigns during Q2 2026.
- vulnerabilitiesRisky Bulletin: A JSON RCE bug is about to rock the Java worldSource ↗
Threat actors are actively exploiting CVE-2026-16723, a remote code execution vulnerability in Alibaba's Fastjson library, a widely used JSON processing tool in Java applications. Exploitation began after security details were disclosed by FearsOff and documented by Imperva and ThreatBook. The flaw enables unauthenticated attacks against Java projects that include Fastjson as a dependency.
- vulnerabilitiesAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionSource ↗
Adobe released security updates for Campaign Classic addressing CVE-2026-48449, a CVSS 10.0 vulnerability involving incorrect authorization that enables arbitrary code execution without user interaction. The flaw affects the enterprise marketing automation platform and requires immediate patching.
| The Gentlemen | 54 claims | +20 vs prior week |
| Qilin | 37 claims | -3 vs prior week |
| Crpxo | 31 claims | +31 vs prior week |
| Everest | 21 claims | +21 vs prior week |
| Booba Team | 16 claims | +16 vs prior week |
| INC Ransom | 13 claims | +9 vs prior week |
| Nightspire | 12 claims | +11 vs prior week |
| Genesis | 11 claims | +5 vs prior week |
| LockBit | 9 claims | +9 vs prior week |
| Safepay | 9 claims | -2 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- CVE-2025-68686Fortinet FortiOSdue
- CVE-2026-18577N-able N-centraldue
- CVE-2026-16812Arista VeloCloud Orchestratordue
- CVE-2026-20316Cisco Secure Firewall Management Center (FMC)due
- CVE-2026-12569PTC Windchill and FlexPLMEPSS up 28 points in about a week
- CVE-2023-3824PHP PHPEPSS up 13 points in about a week
- CVE-2025-68686Fortinet FortiOSAdded to CISA KEV 2026-07-27; Added to VulnCheck KEV 2026-07-27; Added to ENISA EUVD 2026-07-27
- CVE-2026-50522Microsoft SharePointEPSS up 19 points in about a week
- CVE-2026-16232Check Point SmartConsoleEPSS up 59 points in about a week
- claimPhilippine Savings BankUnverified claim. Claimed by The Gentlemen.
- claimWorld Wide FittingsUnverified claim. Claimed by The Gentlemen.
- claimChemco SystemsUnverified claim. Claimed by The Gentlemen.
- claimTotal Auto Business SolutionsUnverified claim. Claimed by The Gentlemen.
- claimOkovolt SolartechnikUnverified claim. Claimed by The Gentlemen.
- claimAmicellUnverified claim. Claimed by The Gentlemen.
- claimPaula FishUnverified claim. Claimed by The Gentlemen.
- claimKnownUnverified claim. Claimed by The Gentlemen.
- claimINTERTRUST AUSTRALIA PTY LTDUnverified claim. Claimed by Qilin.
- claimAsset Flooring Group AustraliaUnverified claim. Claimed by Qilin.
- claimMairie de DrancyUnverified claim. Claimed by Qilin.
- claimThe Saturday Evening PostUnverified claim. Claimed by Qilin.
- claimCommercial Furniture InteriorsUnverified claim. Claimed by Qilin.
- claimDienst Pack SystemsUnverified claim. Claimed by Qilin.
- claimCeragresUnverified claim. Claimed by Qilin.
- claimPointe Property GroupUnverified claim. Claimed by Qilin.
- claimEncore Enterprises, Inc.Unverified claim. Claimed by Crpxo.
- claimKUVEYT TURKUnverified claim. Claimed by Crpxo.
- claimFINANSBANKUnverified claim. Claimed by Crpxo.
- claimANADOLUBANKUnverified claim. Claimed by Crpxo.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.