Here are today’s top cybersecurity stories for Monday, July 27, 2026.
Hermes AI Agent Deployed for Unattended Post-Exploitation at Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended YOLO mode to automate post-exploitation at Thailand’s Ministry of Finance. Hunt.io and researcher Bob Diachenko found an exposed web directory holding 585 files and 470 MB of attacker data — exploit code, web shells, stolen credentials, and Hermes call logs showing the agent performed kernel vulnerability scanning, LinPEAS enumeration, and recursive filesystem traversal, accessing personnel records dating back to 2012. BleepingComputer
vBulletin CVE-2026-61511: Public Pre-Auth RCE Exploit Now Available
A public proof-of-concept exploit dropped July 27 showing how an unauthenticated request reaches PHP’s eval() function inside vBulletin’s template engine and executes arbitrary code with no account or user interaction required. Versions 6.2.1 and 6.1.6 and earlier are affected. vBulletin patched the flaw in version 6.2.2 on July 1, but many operators have not upgraded. No in-the-wild exploitation has been confirmed and the CVE is not on CISA’s KEV catalog. The Hacker News
n8n Patches High-Severity Sandbox Escape Allowing Authenticated OS Command Execution
n8n disclosed and patched GHSA-gv7g-jm28-cr3m (CVSS 8.7), an expression-sandbox escape letting any authenticated user with workflow creation or modification rights run OS commands at the privilege level of the n8n process. Security Joes found the bypass while probing n8n’s February 2026 fix for CVE-2026-27577. Fixed versions are 2.31.5 and 2.32.1. All prior versions in both the 2.31.x and 2.32.x lines are vulnerable. The Hacker News
TELESHIM: East Asia-Linked Threat Actor Targets Middle East Governments via Telegram C2
Zscaler ThreatLabz documented a new campaign attributed with moderate-to-high confidence to an East Asia-based threat actor targeting government entities in the Middle East. The attack chain starts with an ISO file that sideloads TELESHIM, a Windows backdoor that abuses the Telegram API for command-and-control to blend with legitimate traffic, while also deploying MIXEDKEY and BINDCLOAK second-stage payloads. No known threat actor attribution has been made. The Hacker News
Hacked Hotel and Conference Centre Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has compromised Wi-Fi gateways at hotels and conference centres across the US, India, and Saudi Arabia, using adversary-in-the-middle techniques to intercept traffic and steal corporate credentials from business travellers. Activity has been ongoing since at least June 2026 and continues. Organizations sending staff to shared-venue events in these regions face active credential interception risk. SecurityWeek
Coca-Cola Confirms Fairlife Data Breach After Anubis Ransomware Attack
Coca-Cola has confirmed a data breach at its Fairlife dairy subsidiary following the ransomware attack disclosed July 16, when production at US Fairlife facilities was suspended. The Anubis ransomware group claimed 1 TB of stolen data and listed Fairlife on its leak site July 20. The formal breach confirmation extends the scope of an incident first reported the previous week. SecurityWeek
Exposed Operator Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Campaign
Rapid7 recovered 1,048 files from an exposed server belonging to a phishing operator it calls CodeRRR, linking an LLM-assisted toolkit to a live WebDAV campaign delivering a .NET infostealer to Windows users in Mexico via a fake government ID-lookup site. The panel logged 77,098 requests from 3,892 unique IPs over roughly 5.5 days, with Mexico driving 82.5% of traffic. READMEs, lure templates, and campaign mapping files carry hallmarks of LLM-generated content. The Hacker News
GitHub Cuts Bug Bounty Payouts by Half, Moves Top Rewards to Invite-Only VIP Tier
GitHub’s public bug bounty program restructured its payout table effective July 27, cutting rewards by at least 50% at every severity level. Critical findings drop from a $20,000–$30,000+ range to a fixed $10,000, while a permanent invite-only VIP tier pays $30,000 or more. Reports filed before today retain previous payout terms. GitHub says the change is designed to reduce low-quality submissions and give established researchers faster access to its security engineering team. The Hacker News
Stay tuned for today’s in-depth analysis posts.






