Here are today’s top cybersecurity stories for Friday, July 24, 2026.
Certighost: Working Exploit Lets Any Domain User Take Over a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working proof-of-concept on July 24 for CVE-2026-54121, a CVSS 8.8 Active Directory Certificate Services flaw dubbed Certighost. The exploit allows a standard domain account to request a certificate for a Domain Controller, use it to authenticate as the machine, and then extract the krbtgt secret via DCSync — giving an attacker full domain control. Microsoft patched the issue during Patch Tuesday on July 14. The Hacker News
Russian Laundry Bear Group Exploits Zero-Click Zimbra Flaw to Steal NATO Emails and 2FA Codes
CISA, NSA, and FBI issued joint advisory AA26-204A warning that the Russian espionage group Laundry Bear (also tracked as Void Blizzard) has been exploiting CVE-2025-66376, a cross-site scripting flaw in Zimbra Collaboration Suite, since at least July 2025. A single email preview triggers the exploit, automatically exfiltrating the victim’s last 90 days of email, credentials, Global Address List, and two-factor authentication tokens. Confirmed targets include government, defence, energy, and media organizations across the US, Ukraine, and other NATO member states. Synacor patched the flaw in November 2025. BleepingComputer
AgentForger: A Single Phishing Link Could Deploy a Rogue AI Agent Inside Your Organization
Zenity Labs disclosed AgentForger, a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a malicious link to silently create an attacker-controlled AI agent with full employee-level permissions and all approval requirements disabled. The agent could map the organization’s environment, harvest files and credentials, impersonate employees, and spawn additional compromised agents. OpenAI patched the flaw on June 8 following responsible disclosure. The Hacker News
APT28-Linked Campaign Poisons Hotel Wi-Fi DNS to Harvest Corporate Microsoft 365 Credentials
ReliaQuest researchers published findings on July 24 describing a cyber espionage campaign that compromises hotel and conference-venue Wi-Fi gateways to redirect all DNS traffic through attacker-controlled servers. Victims attempting to reach any website are silently sent to lookalike Microsoft 365 login pages. Tradecraft matches previous APT28 (Forest Blizzard / Fancy Bear) campaigns. Compromised gateways were identified across multiple US cities and internationally, with activity ongoing since at least June 2026. Sectors affected include financial services, legal, healthcare, and energy. BleepingComputer
FakeGit: 7,600 Fake GitHub Repositories Spread SmartLoader Malware Via AI and MCP Server Lookalikes
Threat researchers uncovered FakeGit, a campaign using roughly 7,600 malicious GitHub repositories — 800 of which impersonate AI skills or Model Context Protocol (MCP) servers — to distribute SmartLoader malware. The repositories have accumulated more than 14 million downloads across GitHub Release assets and appeared in over 600 public AI registries and catalogs, a technique researchers call “agentbaiting.” SmartLoader installs StealC, an information stealer targeting credentials and active sessions. The campaign is attributed to threat actor Water Kurita. The Hacker News
Hackers Exploit Windmill CVE-2026-29059 to Read Arbitrary Server Files; FCEB Deadline Today
Attackers are actively exploiting CVE-2026-29059, a path traversal flaw in Windmill, an open-source workflow automation platform, to read sensitive server files including /etc/passwd without authentication. Approximately 170 systems in 24 countries remain exposed. The vulnerability was patched in Windmill 1.603.3 in January 2026. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a Federal Civilian Executive Branch remediation deadline of July 24, 2026. The Hacker News
Nayax Refuses Ransom After The Syndicate Claims 100 TB Stolen Including Over 1 Billion Card Records
Payment technology company Nayax confirmed a security incident involving a subsidiary’s cloud account after threat actor group The Syndicate claimed to have spent nearly a year inside Nayax systems, exfiltrating more than 100 terabytes of data including over one billion payment card records, customer KYC data, transaction histories, source code, and internal API keys. Nayax stated its production environment and core systems were not compromised, all customer funds are protected, and it will not pay the extortion demand. DataBreaches.net
Clop Ransomware Publishes Victims From Windchill and FlexPLM Exploitation Campaign
The Clop ransomware group has begun publishing data from victims in a campaign exploiting CVE-2026-12569, a critical deserialization flaw in PTC Windchill and FlexPLM product lifecycle management platforms. Confirmed victim sectors include manufacturing, automotive, aerospace, and retail. CISA added CVE-2026-12569 to its KEV catalog in late June following reports of web shell deployment. Clop is now extorting organizations by threatening to release stolen product design and engineering data. BleepingComputer
Stay tuned for today’s in-depth analysis posts.






