Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Tuesday, July 21, 2026

Here are today’s top cybersecurity stories for Tuesday, July 21, 2026.

Qilin Ransomware Gangs Exploit Palo Alto PAN-OS Authentication Bypass CVE-2026-0257
Arctic Wolf Labs investigated multiple June 2026 intrusions in which threat actors exploited CVE-2026-0257, an authentication bypass flaw in the Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVSS 7.8), to deploy Qilin ransomware. Attackers established unauthorized VPN sessions, dumped LSASS and NTDS credentials, moved laterally via PsExec and RDP, and in several cases exfiltrated data to MEGA via Rclone before encrypting systems. Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2 prior to patched builds. The Hacker News

JADEPUFFER Returns With ENCFORGE Ransomware Built to Destroy AI Model Files
Sysdig researchers linked a second attack on a compromised Langflow server to JADEPUFFER, the AI-agent-driven threat operator first documented on July 7. The operator deployed ENCFORGE, a new Go-compiled ransomware targeting approximately 180 file extensions including .ckpt, .safetensors, .onnx, .gguf, .faiss, .parquet, .pkl, and .pt — formats covering AI model weights, vector indexes, training datasets, and ML pipeline files. The initial access vector remains CVE-2025-3248, an unauthenticated code execution flaw in Langflow (CVSS 9.8) listed in CISA’s KEV catalog. The same Proton Mail extortion address from the July 7 campaign links both attacks to the same operator. Help Net Security

SonicWall Zero-Days CVE-2026-15409/CVE-2026-15410 Were Exploited Weeks Before Patch
Volexity revealed today: UTA0533 began exploiting CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 appliances as early as June 22 — more than three weeks before SonicWall’s July 14 advisory. Attackers installed two custom malware tools: ROOTRUN, a privilege-escalation binary, and KNUCKLEBALL, a Python-based loader injecting hidden Java components into a legitimate running SonicWall process for persistent in-memory access. Organizations patched after July 14 should investigate for signs of earlier compromise. Help Net Security

Gitea CVE-2026-58443: Critical Auth Bypass Lets Public Tokens Write to Private Repos
A critical authorization bypass flaw in Gitea allows an attacker holding only a public repository access token to push changes into private pull request branches and trigger private Actions workflows. The flaw exists in the PR update API endpoint, which validates the token against the public base repository rather than the private target. No elevated privileges beyond a standard Gitea account are required. The vulnerability is fixed in Gitea v1.27.0. CybersecurityNews

Estee Lauder Discloses Oracle EBS Breach: SSNs, Passport Numbers, and Health Data Stolen
The Estee Lauder Companies began notifying current and former employees this week of a breach of its Oracle E-Business Suite HR environment breached in August 2025. Attackers linked to the Clop ransomware group exploited CVE-2025-61882 to access and exfiltrate Social Security numbers, passport numbers, financial records, and health data. The company confirmed the intrusion on June 19, 2026 after an investigation with external cybersecurity specialists. Affected individuals are being offered 24 months of free identity monitoring through Kroll. Help Net Security

Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting
The Linux kernel security team published 440 CVE advisories within a single 24-hour window on July 19 and 20, the largest single-day vulnerability disclosure volume in the project’s history. The surge is attributed to AI-powered vulnerability analysis tools operating faster than human review cycles. Affected subsystems include XFS, Btrfs, Netfilter, Bluetooth, KVM, NVMe, CIFS/SMB, Wi-Fi drivers, DMA mapping, RDMA, and IOMMU. Vulnerability classes include use-after-free, out-of-bounds access, NULL-pointer dereferences, and race conditions. Linux administrators and container operators should prioritize upstream updates. SecurityOnline

Interlock Ransomware Claims 380 GB of Data From Canadian Immigration Nonprofit Centre for Newcomers
The Interlock ransomware group listed Centre for Newcomers, a Calgary-based nonprofit providing immigration and settlement services across Alberta, on its dark web leak site. Interlock claims to have stolen 380 GB of data including personal client records, company financial information, current-status reporting, and HR planning documents. The attack came to light on July 20, 2026. No ransom payment or recovery status has been publicly disclosed. DeXpose

OpenClaw: A Single WhatsApp Message Chains Three Flaws Into Host-Level Code Execution
Security researcher Chinmohan Nayak disclosed a three-vulnerability attack chain in the OpenClaw personal AI assistant converting a WhatsApp message into host-level code execution. The root issue lies in OpenClaw’s sanitizeEnvVars() function, which filtered environment variables passed to spawned processes but failed to account for interpreter startup variables including NODE_OPTIONS, PYTHONSTARTUP, and BASH_ENV. All three flaws are patched in OpenClaw version 2026.6.6; users on earlier versions should update immediately. The Hacker News

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.