Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Thursday, July 23, 2026

Here are today's top cybersecurity stories for Thursday, July 23, 2026.

Check Point CVE-2026-16232: Actively Exploited SmartConsole Zero-Day Gets CISA Deadline of July 25
Check Point Software has patched an authentication bypass in its SmartConsole GUI, tracked as CVE-2026-16232 (CVSS 9.1), after confirming active exploitation against management servers exposed to the internet. An unauthenticated attacker obtains a login token granting full administrator access to the Security Management Server, enabling security policy modification or firewall rule deletion without any credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a July 25, 2026 remediation deadline for federal agencies.
BleepingComputer

RefluXFS CVE-2026-64600: 9-Year-Old Linux XFS Race Condition Exposes 16.4 Million Systems to Root Takeover
Qualys has disclosed RefluXFS, a race condition in the Linux kernel's XFS filesystem copy-on-write path dating back nine years, which lets any local user overwrite protected files and gain root privileges. The exploit leaves no kernel log output, survives reboots, and bypasses SELinux Enforcing mode, affecting RHEL, Oracle Linux, Amazon Linux, and Fedora Server across an estimated 16.4 million systems. The upstream kernel fix merged on July 16, 2026, and distributions are actively issuing backported patches.
BleepingComputer

Chaos Ransomware Deploys msaRAT Backdoor Hiding C2 Traffic Inside Chrome and Edge Browsers
Cisco Talos has documented msaRAT, a Rust-based remote access trojan used by the Chaos ransomware group, which routes encrypted command-and-control traffic through headless Chrome or Edge processes via WebRTC and Cloudflare developer infrastructure. The malware controls the browser through the Chrome DevTools Protocol, making C2 traffic indistinguishable from ordinary browser cloud activity and invisible to most network-layer detection tools. Chaos operators gain initial access through spam floods, vishing, and Quick Assist abuse before deploying the backdoor.
Cisco Talos

JadeProx: China-Nexus Espionage Cluster Used TriBack Loader Against Governments and Hospitals Across Asia and Latin America
Group-IB has published research on JadeProx, a China-nexus threat cluster uncovered when an exposed Alibaba Cloud server in Singapore was found holding operational data, including a previously undocumented Windows loader called TriBack Loader. Confirmed intrusions include a Vietnamese public hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, and a spear-phishing package targeting the National Congress of Honduras. The cluster used Chinese offensive tooling including iox, Neo-reGeorg, suo5, nuclei, and fscan for tunneling, pivoting, and mass reconnaissance.
The Hacker News

Upbound Group Says Acima Breach Led to $13 Million in Fraudulent Lease-to-Own Agreements
Upbound Group, parent company of lease-to-own service Acima, disclosed a data breach in which stolen customer records were used to generate approximately $13 million in fraudulent lease agreements during Q2 2026. Attackers obtained customer information without authorization and placed fake lease-to-own orders, with Acima paying out merchandise to fraudsters who then disappeared without making payments. The company has notified federal law enforcement and implemented enhanced authentication controls and fraud-detection mechanisms.
BleepingComputer

South Korea Discloses 10-Month Diplomatic Academy Breach Exposing Data of Up to 10,000 Foreign Ministry Personnel
South Korea has disclosed a data breach at the Korea National Diplomatic Academy lasting approximately ten months from April 2025 to February 2026, in which attackers exploited a zero-day vulnerability to access personal data of up to 10,000 current and former Ministry of Foreign Affairs employees, including overseas diplomats. Compromised records include names, user IDs, email addresses, encrypted passwords, positions, and departmental affiliations, though no sensitive identification numbers or internal government systems were accessed. South Korea's National Intelligence Service detected the breach in February 2026, and no confirmed misuse has been reported.
BleepingComputer

GitHub Actions Weaponized to Exploit cPanel CVE-2026-41940 Authentication Bypass at Scale Across Hosting Infrastructure
Attackers compromised a PHP developer's GitHub account and injected 583 malicious GitHub Actions workflow files across ten Packagist packages between July 12 and 13, 2026, turning the PHP ecosystem into distributed scanning and exploitation infrastructure. Each workflow launches a GitHub-hosted runner, downloads an architecture-specific payload, and targets exposed cPanel and WHM servers through CVE-2026-41940, a critical authentication bypass, to harvest server credentials and administrative secrets. Internet-facing hosting environments running unpatched cPanel and WHM installations are the primary targets.
The Hacker News

Researchers Expose SharedRoot: Claude Cowork Sandbox Escape Lets Attackers Access Host Mac and Windows Filesystems
Security researchers have disclosed SharedRoot, a sandbox escape vulnerability in Anthropic's Claude Cowork, which chains exploitation of CVE-2026-46331 in the agent's guest Linux kernel to break out of the VM and read or write files across the host Mac filesystem as the logged-in desktop user. A separate Windows variant exploits design flaws in the CoworkVMService RPC interface to achieve root-level command execution inside the Hyper-V-isolated Ubuntu VM. Anthropic has patched both variants.
The Hacker News

Adobe Patches HermeticReader CVE-2026-48294: Flaw in 329-Million-Install Acrobat Extension Exposed WhatsApp Web Chats
Adobe has patched CVE-2026-48294 in its Acrobat Chrome extension, a flaw allowing a malicious website to inject a form into WhatsApp Web, capture the live chat body, and submit rendered messages, contact names, and conversation previews to an attacker-controlled server. The attack required no malware, no stolen credentials, and no WhatsApp vulnerability — a victim simply visiting a malicious page while signed into WhatsApp Web with the affected extension installed was sufficient. The extension has approximately 329 million installs, and Adobe released a patch within one weekend of responsible disclosure.
SecurityWeek

Theori Finds 434 Exploitable Vulnerabilities in 28 AI-Generated Applications
Theori has published research on vibe-coded applications built across multiple AI models and development environments, identifying 434 verified exploitable security vulnerabilities after runtime testing and source-code review. The most common issues were insufficient rate limiting, insecure direct object references (IDOR), server-side request forgery (SSRF), and directory traversal, with modern AI models producing fewer SQL injection flaws but consistently missing authorization controls and secrets management. Five models from Anthropic and OpenAI were used across both greenfield and brownfield development scenarios.
SecurityWeek

Stay tuned for today's in-depth analysis posts.

Enjoy this article? Don’t forget to share.