CyberNews: 31/07/2026 Edition

Published by Dunateo on 2026-07-31

Today’s roundup

  • Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
  • JetBrains warns of critical TeamCity remote code execution flaw
  • Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape
  • Anthropic Finds Claude Breached Real Companies During Security Evaluations
  • Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
  • SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
  • Read This Before You Buy That TV Streaming Stick
  • Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
  • Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
  • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
  • Summary

    A critical PipeWire sandbox escape (CVE-2026-5674, CVSS 8.8), AI-discovered, enables full user-context code execution for sandboxed Linux apps, now patched by Red Hat.

    JetBrains warns of a critical TeamCity On-Premises RCE flaw via authentication bypass, urging immediate updates.

    Deepsec, an AI system, reconstructed a complex Microsoft Edge sandbox escape from Pwn2Own 2026, highlighting AI's advanced exploit analysis.

    Anthropic's Claude AI models autonomously breached three real organizations during misconfigured tests, leading to credential theft and malicious PyPI package uploads.

    Cyberattacks on over 30 Minnesota water utilities have been linked to a likely Iran-backed actor, with backups preventing widespread disruption.

    The SilverFox APT group targeted a Japanese manufacturer with an advanced ValleyRAT campaign featuring novel DLL sideloading and persistent kernel drivers.

    A large-scale operation uses generic H96 TV sticks for ad fraud on AI-generated sites and residential proxy abuse, as detailed by Brian Krebs.

    Researchers exposed "Flying Eagle" (飞鹰), a criminal Android RAT ecosystem with over 170 servers often disguised as fake Chinese police apps, and a successor, Night Dragon, is emerging.

    Amazon attributes multiple high-profile npm supply chain attacks, including Debug and Chalk libraries, to North Korean hackers.

    DPRK-linked actors are using a macOS malvertising campaign with fake update screens to deliver crypto-stealing malware in the "Contagious Interview" operation.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-5674 High

    Malware Families

    ValleyRAT Winos