This day 02:09 06:09 10:09 14:10 18:01 22:01
Info  2026-07-31 18:01Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-07-31 — Data Center OT Exposed, AI Threats Mature

Executive summary: A systemic weakness in data-center building-management protocols — ~90% running without encryption or authentication — gives attackers a shortcut to physical disruption without touching servers. ESET's latest threat report confirms malicious AI is moving from novelty to operational tooling, while Google's AI-assisted Chrome fuzzing programme patches a record 1,442 bugs across three releases. Law-enforcement infrastructure also advances: Interpol's global anti-fraud payment system and California's new DROP data-deletion platform both go live this month.

Top items

Themes

AI as a dual-use force multiplier. ESET's report on malicious AI skills and Google's record AI-assisted fuzzing results (1,072 of 1,442 bugs found via AI) illustrate both sides of the same coin — offensive AI is maturing into operational tooling while defensive AI is dramatically expanding vulnerability discovery. Teams should expect attacker AI capabilities to advance in parallel.

Unauthenticated OT protocols remain systemic. The data-centre cooling finding mirrors the pattern CISA flagged for water-utility PLCs: critical infrastructure routinely runs management protocols without encryption or authentication. Whether it's building-management systems or industrial controllers, the attack surface is less about sophisticated exploits and more about reaching networks that were never designed to be exposed.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb