Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 40 most important stories from July 13–17, 2026.
What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome exploit on its own, and two Scattered Spider hackers went to prison in the UK’s largest cybercrime prosecution.
From actively exploited SonicWall appliances to a RAT hunting 40 crypto wallets, here’s everything your peers are reading this week.
What cybersecurity stories are covered
Top Stories of the Week — 5 stories
AI Under Attack — 6 stories
Critical Vulnerabilities & Patches — 12 stories
Malware & APT Campaigns — 9 stories
Phishing & Identity Attacks — 4 stories
Supply Chain & Industry News — 4 stories
🔥 TOP STORIES OF THE WEEK
1. Microsoft Patch Tuesday July 2026 – Record 570 Vulnerabilities Patched
July 15, 2026 • gbhackers.com
Microsoft shattered its all-time record with 570 vulnerabilities fixed in a single Patch Tuesday. Admins face one of the heaviest patching workloads in the company’s history — here’s what to prioritize first.
2. Critical SonicWall SMA 1000 SSRF and Remote Code Execution Flaws Actively Exploited in the Wild
July 15, 2026 • gbhackers.com
Attackers are actively exploiting critical SSRF and RCE flaws in SonicWall SMA 1000 appliances. If your remote access gateway isn’t patched yet, assume it’s being scanned right now.
3. Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution
July 17, 2026 • gbhackers.com
Two members of the notorious Scattered Spider crew are behind bars after the UK’s largest-ever cybercrime prosecution. A landmark verdict that ends one chapter of the group’s rampage against major enterprises.
4. China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign
July 15, 2026 • gbhackers.com
State-backed operators are turning commercial AI coding tools into intrusion assistants for government network attacks. The line between developer tooling and attack tooling just disappeared.
5. Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
July 17, 2026 • gbhackers.com
From one compromised Microsoft IIS server to enterprise-wide ransomware in under 24 hours. This incident breakdown shows exactly how fast modern intrusions move — and where defenders lost their window.
🤖 AI UNDER ATTACK
6. GPT-5.6 Sol Ultra Writes Complete Chrome Exploit With V8 Sandbox Escape
July 16, 2026 • gbhackers.com
OpenAI’s newest model produced a working Chrome exploit — including a V8 sandbox escape — with minimal human help. The era of AI-authored zero-days is no longer theoretical.
7. Critical Claude for Chrome Flaw Lets Malicious Extensions Read Gmail, Google Docs, and Calendar
July 15, 2026 • gbhackers.com
A critical flaw in Claude for Chrome allowed rogue extensions to piggyback on the AI agent’s permissions and read Gmail, Docs, and Calendar. Your browser’s smartest assistant nearly became its biggest leak.
8. Hackers Use Google Ads and Claude AI Chats to Steal macOS Credentials and Crypto Wallets
July 16, 2026 • gbhackers.com
A malvertising campaign is combining Google Ads with shared Claude AI chat links to lure Mac users into credential-stealing malware. Even AI chat pages are now part of the phishing kill chain.
9. New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
July 13, 2026 • gbhackers.com
Research shows VEXAIoT AI agents finding and exploiting IoT vulnerabilities on their own with a 95% success rate. Autonomous exploitation at scale has officially arrived.
10. LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures
July 16, 2026 • gbhackers.com
TuxBot’s operators used LLM assistance to compile their botnet for 17 different processor architectures. AI just solved malware’s oldest portability problem.
11. Cursor 0-Day Flaw Executes Malicious git.exe From Repositories Without User Interaction
July 16, 2026 • gbhackers.com
A zero-day in the Cursor AI editor executes a malicious git.exe the moment a booby-trapped repository is opened — no clicks needed. Simply cloning the wrong repo is now a compromise.
⚠️ CRITICAL VULNERABILITIES & PATCHES
12. LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
July 17, 2026 • gbhackers.com
The LegacyHive zero-day lets a standard Windows user load and modify an administrator’s registry classes hive. A quiet path from ordinary account to full privilege escalation.
July 14, 2026 • gbhackers.com
An unauthenticated attacker can escape the ServiceNow AI Platform sandbox and execute remote code. Enterprise workflow automation just became an enterprise-wide attack vector.
14. Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User
July 13, 2026 • gbhackers.com
An OAuth flaw in RabbitMQ hands attackers access to every message, queue, and user account on the broker. The messaging backbone of thousands of apps is exposed.
July 15, 2026 • gbhackers.com
Fortinet shipped fixes for seven flaws spanning nearly its entire security product line. When the security stack itself needs patching, speed matters — update before attackers reverse the patches.
16. Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network
July 15, 2026 • gbhackers.com
Multiple Windows RDP vulnerabilities were leaking sensitive data over the network before this month’s fixes. Remote desktop remains one of the most attacked doors into the enterprise.
17. SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
July 14, 2026 • gbhackers.com
SAP’s July Patch Day addresses critical flaws in NetWeaver, Approuter, and Commerce Cloud. ERP systems run the business — and attackers know exactly what they’re worth.
18. F5 Fixes 3 NGINX Flaws Enabling Potential Remote Code Execution, Memory Disclosure, and DoS Attacks
July 16, 2026 • gbhackers.com
F5 patched three NGINX flaws enabling potential RCE, memory disclosure, and denial of service. NGINX fronts a huge share of the world’s web traffic — this update touches almost everyone.
19. Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
July 16, 2026 • gbhackers.com
Flaws in Splunk Enterprise expose stored credentials and permit arbitrary SPL searches. The platform watching your environment needs watching too.
July 15, 2026 • gbhackers.com
Notepad++ 8.9.7 closes five security holes, including a stack buffer overflow and zip slip flaw. One of the world’s most installed editors deserves a spot in this week’s patch queue.
21. 7-Zip Vulnerability Lets Attackers Trigger Heap Buffer Overflow Using Malicious Files
July 17, 2026 • gbhackers.com
A crafted archive can trigger a heap buffer overflow in 7-Zip the moment it’s processed. The archive tool on nearly every Windows machine just became an attack surface.
22. Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More
July 13, 2026 • gbhackers.com
Debian 13.6 rolls up security fixes across the Linux kernel, Apache, Curl, QEMU, and more. A one-stop update for one of the world’s most deployed server distributions.
23. Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
July 16, 2026 • gbhackers.com
Millions of Shark robot vacuums carry an unpatched remote code execution flaw. The camera-equipped robot roaming your home may be the least secure device you own.
🦠 MALWARE & APT CAMPAIGNS
24. New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
July 17, 2026 • gbhackers.com
The Python-based Starland RAT, run by Russian-speaking actor UAT-11795, harvests browser credentials and hunts more than 40 crypto wallet types. The campaign has been running quietly since June 2025.
25. Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
July 17, 2026 • gbhackers.com
Attackers are smuggling Lua-based loaders inside fake font files to drop Remcos, XWorm, and Agent Tesla. A file format nobody scans just became a delivery vehicle.
26. OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases
July 15, 2026 • gbhackers.com
OkoBot pairs ClickFix social engineering with a ‘SeedHunter’ module built to extract Ledger and Trezor recovery phrases. Hardware wallet owners are the explicit target.
27. Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users
July 17, 2026 • gbhackers.com
Mac users are being talked into pasting a single terminal command that installs the ClickLock stealer. One copy-paste is all it takes to hand over the keychain.
28. GoSerpent Silently Steals Government Files for Weeks Before Sending Them to Hackers
July 17, 2026 • gbhackers.com
GoSerpent sat inside government systems silently collecting files for weeks before exfiltrating them in bulk. Patient, quiet, and devastating — espionage tradecraft at its most effective.
29. China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware
July 16, 2026 • gbhackers.com
The infamous China-linked Daxin backdoor has resurfaced in Taiwan, now accompanied by new SYSTEM-level malware dubbed STUPIG. A significant escalation in an already tense theater.
30. Miasma Worm Returns as RAT-First npm Attack With Automatic Propagation Disabled
July 14, 2026 • gbhackers.com
The Miasma worm is back on npm — reengineered as a RAT-first implant with its self-spreading deliberately switched off. Quieter by design, and harder to catch because of it.
31. BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
July 13, 2026 • gbhackers.com
BusySnake hides its traffic in reverse SSH tunnels and rotates AI-generated loaders to stay ahead of signatures. Machine-written malware variants are now a production-line reality.
32. Russian FSB-Linked Turla Hackers Target French Ministries, Embassies, and Defense Entities
July 13, 2026 • gbhackers.com
FSB-linked Turla is running an active espionage campaign against French ministries, embassies, and defense organizations. One of Russia’s oldest APTs is aiming squarely at NATO’s core.
🎣 PHISHING & IDENTITY ATTACKS
33. Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
July 13, 2026 • gbhackers.com
A misconfigured server blew the cover off Evilginx operators harvesting Microsoft 365 sessions and OAuth tokens at scale. A rare inside look at a live adversary-in-the-middle operation.
34. Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access
July 15, 2026 • gbhackers.com
Attackers are chaining OAuth device-code phishing with rogue Entra ID device enrollment to gain SaaS access that survives password resets. Kicking them out is much harder than letting them in.
35. FaceTime Scammers Combine Credential Theft, Remote-Access Apps, and iOS Exploits for Device Takeover
July 15, 2026 • gbhackers.com
Scammers are cold-calling victims on FaceTime, then stacking credential theft, remote-access apps, and iOS exploits into full device takeover. The friendly video call is the new attack vector.
36. Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
July 14, 2026 • gbhackers.com
Pro-Iran hacktivist groups are combining DDoS barrages with hack-and-leak operations against critical infrastructure. Ideological attackers are borrowing nation-state playbooks.
🔗 SUPPLY CHAIN & INDUSTRY NEWS
37. Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
July 13, 2026 • gbhackers.com
A supply chain attack on Jscrambler’s npm packages was caught stealing cloud credentials and crypto wallet secrets from developer machines. Even security vendors’ packages are now targets.
38. ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
July 14, 2026 • gbhackers.com
The popular ModHeader Chrome extension left 900,000 users exposed to potential browsing history theft. A trusted developer tool quietly became a mass surveillance risk.
39. AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
July 17, 2026 • gbhackers.com
An AWS Cost Explorer bug greeted cloud customers with trillion-dollar bill estimates. Nobody actually owes a trillion dollars — but the panic screenshots are already legendary.
40. ANY.RUN Integrates Threat Intelligence and Interactive Sandbox to Streamline SOC Workflows
July 14, 2026 • gbhackers.com
ANY.RUN merged its threat intelligence feeds with its interactive sandbox into a single SOC workflow. Analysts can pivot from detonation to attribution without leaving the platform.
Other Attacks
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
July 18, 2026 • gbhackers.com
A pre-authentication WordPress Core vulnerability called wp2shell allows anonymous attackers to execute remote code on default installations without valid credentials.
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
July 18, 2026 • gbhackers.com
Ernst & Young confirmed that attackers compromised a third-party IT service management platform and exfiltrated sensitive client tax documents.
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
July 18, 2026 • gbhackers.com
The HollowByte flaw allows unauthenticated attackers to exhaust server memory using a specially crafted payload measuring only 11 bytes
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
July 18, 2026 • gbhackers.com
Two high-severity Citrix Secure Access Client vulnerabilities allow local Windows users to elevate their privileges to SYSTEM.
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
July 17, 2026 • gbhackers.com
The Python-based Starland RAT steals browser credentials, collects sensitive information and searches infected devices for more than 40 cryptocurrency wallets.
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
July 17, 2026 • gbhackers.com
Threat actors disguise malicious Lua loaders as TrueType Font files to distribute Remcos RAT, XWorm and Agent Tesla.
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
July 17, 2026 • gbhackers.com
The LegacyHive Windows vulnerability allows attackers to manipulate administrator registry hives and escalate local privileges.
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
July 17, 2026 • gbhackers.com
Attackers used a compromised Microsoft IIS server as an initial foothold before deploying ransomware throughout the victim’s network.
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
July 17, 2026 • gbhackers.com
An AWS Cost Explorer error displayed inaccurate estimated charges reaching trillions of dollars, although customers were not actually billed those amounts.
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws
July 13, 2026 • gbhackers.com
CISA added unrestricted file-upload vulnerabilities affecting iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog.
❓ FREQUENTLY ASKED QUESTIONS
What does this weekly cybersecurity newsletter cover?
Each issue of the GBHackers cybersecurity newsletter rounds up the week’s 40 most important stories — critical vulnerabilities, ransomware attacks, data breaches, AI security threats, phishing campaigns, and malware research — curated by our editorial team from everything published on gbhackers.com.
How is a cybersecurity bulletin different from daily security news?
A cybersecurity bulletin condenses hundreds of daily headlines into a single prioritized weekly briefing. Instead of monitoring feeds all day, security teams get the exploited CVEs, active campaigns, and breaches that actually matter — with direct links to the full analysis of each story.
How do I subscribe to the GBHackers weekly cybersecurity newsletter?
Visit gbhackers.com and follow us on LinkedIn or X (@gbhackers_news) to get every weekly issue. The newsletter is free and lands once a week, every week.





