Infosec bits for 2026 week 31
Heloise Meyer
| July 31, 2026, 2:48 p.m.
Cybersecurity News:
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreen [Group-IB, Group-IB]
Beyond the screenshot: Why you should verify what you see [Phil Muncaster, ESET]
Exposed credentials are giving attackers a head start many organizations don’t see [Anamarija Pogorelec, HelpNetSecurity]
Vulnerabilities & Patches:
Breaking the Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch [Security Joes, Security Joes]
Thousands of Data Center Controllers Open to Takeover [Jai Vijayan, Dark Reading]
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched [Alessandro Mascellino, Infosecurity Magazine]
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape [Ravie Lakshmanan, The Hacker News]
libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory [Do Son, Daily CyberSecurity]
Cyberattacks:
Microsoft Teams vishing attacks lead to Chaos ransomware attacks [Lawrence Abrams, Bleeping Computer]
Rogue AI:
OpenAI says its rogue AI tried to hack other companies [Joe Tidy, BBC]
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations [Ravie Lakshmanan, The Hacker News]
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard [Alessandro Mascellino, Infosecurity Magazine]