DJBSEC's CyberNews 2026-07-29

Today’s daily news covers the following categories: Authentication Vulnerability Data Breach Privacy Malware Threat Intelligence


Password Resets Alone Are No Longer Enough to Stop Modern Cyberattacks

Authentication Security experts are warning that simply resetting passwords is no longer sufficient to stop many modern cyberattacks. Threat actors increasingly steal authentication tokens, session cookies, and other credentials that allow them to maintain access even after a password has been changed. Researchers recommend adopting phishing-resistant multi-factor authentication, passkeys, continuous session monitoring, and rapid token revocation as part of a broader identity security strategy. Organizations are also encouraged to monitor for suspicious login activity rather than relying solely on credential resets after an incident. The report highlights how identity attacks have evolved beyond traditional password theft.

Critical OpenWrt DHCPv6 Vulnerability Enables Remote Code Execution

Vulnerability Researchers have disclosed a critical vulnerability affecting OpenWrt’s DHCPv6 implementation that could allow remote attackers to execute arbitrary code on vulnerable devices. Because OpenWrt is widely deployed on routers and embedded networking equipment, successful exploitation could provide attackers with control over network infrastructure. Maintainers have released updates addressing the flaw and are urging administrators to patch affected systems immediately. Internet-facing routers remain attractive targets because they often provide a gateway into enterprise and home networks. The discovery underscores the importance of promptly updating network infrastructure software.

Apple Releases iOS 26.6 Security Update Addressing Multiple Vulnerabilities

Vulnerability Apple has released iOS 26.6, fixing multiple security vulnerabilities affecting iPhones and other supported devices. The update addresses flaws that could potentially be exploited to compromise device security, elevate privileges, or execute malicious code. Apple is encouraging users to install the update as soon as possible to reduce exposure to potential attacks. As with previous security releases, the company provided fixes across several system components rather than a single issue. Keeping mobile devices fully patched remains one of the most effective ways to defend against emerging threats.

ShinyHunters Threatens Ernst & Young and EY Over Alleged Data Breach

Data Breach The ShinyHunters cybercrime group has claimed responsibility for breaching systems associated with Ernst & Young and has threatened to leak allegedly stolen data. At the time of reporting, the claims were still being investigated, and the full scope of any potential compromise had not been independently verified. If confirmed, the incident could expose sensitive corporate or client information and add another high-profile victim to the group’s growing list of targets. Organizations are closely monitoring the situation as investigators work to determine the validity of the claims. The incident demonstrates how extortion groups continue using public leak threats to pressure organizations during breach investigations.

CertiGhost Active Directory Certificate Flaw Creates New Attack Path

Vulnerability Researchers have disclosed a newly named vulnerability called CertiGhost that affects Microsoft Active Directory Certificate Services environments. The flaw could allow attackers to abuse certificate-based authentication, potentially escalating privileges or impersonating legitimate users under certain conditions. Because many organizations rely on Active Directory certificates for identity and authentication services, the issue poses significant enterprise risk if left unaddressed. Security teams are encouraged to review certificate configurations, apply available mitigations, and audit privileged certificate templates. The research highlights the growing focus on attacks targeting enterprise identity infrastructure.

New Chrome Extension Monitors AI Conversations for Sensitive Data

Privacy Researchers have introduced a Chrome extension designed to monitor interactions with AI assistants and identify when sensitive information may be shared during conversations. The tool analyzes prompts and responses in real time to help users avoid unintentionally exposing confidential business or personal data. As organizations increasingly adopt generative AI platforms, preventing accidental data disclosure has become a growing security concern. The extension is intended to provide an additional layer of awareness rather than replace existing data loss prevention controls. The project reflects the increasing emphasis on protecting information shared with AI services.

Researchers Identify Cryptographic Weaknesses in Claude Mythos

Vulnerability Security researchers have identified cryptographic weaknesses affecting the Claude Mythos framework that could reduce the effectiveness of certain security protections if left unresolved. The findings focus on implementation issues rather than a fundamental break in modern cryptographic algorithms. Developers have been advised to review affected components and apply recommended updates or configuration changes where appropriate. Researchers emphasized that strong cryptography remains effective when implemented correctly, making secure engineering practices essential. The disclosure serves as a reminder that implementation flaws can be just as significant as software vulnerabilities.

Dysphoria Botnet Hides Command Infrastructure Using Blockchain Domains

Malware Researchers have found that the Dysphoria botnet is using blockchain-based domain services to conceal its command-and-control infrastructure from traditional security monitoring. By leveraging decentralized naming systems, the operators make it more difficult for defenders to disrupt communications or seize malicious infrastructure. The technique demonstrates how malware developers continue adopting new technologies to improve resilience against law enforcement and security operations. Organizations are encouraged to monitor outbound network traffic for unusual connections and strengthen endpoint detection capabilities. The findings highlight the ongoing evolution of botnet infrastructure.

Fortinet Introduces New FortiGate Platform Combining Firewall and SASE

Threat Intelligence Fortinet has unveiled a new FortiGate platform that combines traditional next-generation firewall capabilities with Secure Access Service Edge, or SASE, functionality. The integrated approach is designed to simplify security management for organizations supporting hybrid workforces and distributed environments. Fortinet says the platform provides centralized policy enforcement while improving visibility across branch offices, remote users, and cloud resources. Industry analysts view the announcement as part of the continuing convergence of networking and cybersecurity technologies. The release reflects growing demand for unified security platforms that reduce operational complexity.

OpenAI Open-Sources Codex Security CLI

Threat Intelligence OpenAI has released the Codex Security CLI as an open-source project, giving developers and security professionals a command-line tool for integrating AI-assisted security capabilities into their workflows. The utility is designed to support tasks such as code analysis, vulnerability review, and security automation while allowing organizations to inspect and extend the underlying code. By making the project open source, OpenAI aims to encourage community contributions, transparency, and broader adoption of AI-assisted security tooling. Security researchers believe the release could accelerate innovation in secure software development and automated vulnerability analysis. The announcement reflects the growing role of open AI tools in modern cybersecurity operations.




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-28
  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24