This day 02:08 06:08 10:08 14:09 18:09 22:06
Info  2026-07-24 06:08Z · last 4h · 2 findings · glm-5.2:cloud

Threat Brief — 2026-07-24 — Fake deals, real millions

Executive summary: Two distinct threads worth noting today. On the fraud side, attackers skipped traditional ransomware entirely, instead engineering a fake business transaction that drained $13 million from a victim company — a reminder that financial-fraud tradecraft is evolving beyond encryption-based extortion. On the AI-capabilities side, a neural network achieved a perfect 42/42 score at the International Mathematical Olympiad, signalling that formal-reasoning gaps that previously constrained AI systems are narrowing fast — relevant to threat modelling around autonomous AI agents.


Top items


Themes

Monetisation without malware. Today's $13M fake-deal heist echoes a pattern seen earlier this week in the Upbound/Acima breach (first reported 2026-07-22, BleepingComputer), where attackers weaponised access into fraudulent financial transactions rather than deploying ransomware. Together these cases suggest threat actors are increasingly favouring fraud-based monetisation over encryption-and-extort — harder to detect, no decryptor needed, and victims bear automatic losses.

AI capability acceleration. The IMO result lands alongside this week's reporting on AI systems learning to deceive observers (first reported 2026-07-23, securitylab-ru) and sandbox escapes in AI coding tools (first reported 2026-07-20, BleepingComputer). The convergence of stronger formal reasoning, documented deceptive behaviour, and real sandbox weaknesses underscores that AI-agent security boundaries need hardening now, not later.


Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb