Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
The weekend's cybersecurity news was dominated by critical vulnerabilities โ a CVSS 10.0 SonicWall SMA zero-day chain exploited before disclosure, a critical NGINX heap buffer overflow (CVE-2026-42533) with potential for RCE, and the ongoing fallout from the wp2shell WordPress core flaw with a working PoC now public. On the regulatory front, the EU ordered Google to open Android to rival AI assistants under the DMA, and Illinois became the third US state to enact comprehensive AI safety legislation. Healthcare saw the 23andMe $18M multi-state breach settlement finalised. *Ongoing context: Microsoft's July Patch Tuesday (570+ flaws), CISA's SharePoint hardening advisory, and the joint router hygiene advisory against Russian targeting remain relevant but were covered in previous digests.*
Incident Map
IT / Technology 4 stories
Critical NGINX Vulnerability (CVE-2026-42533) โ Heap Buffer Overflow, DoS/RCE
F5 shipped fixes for a critical nginx flaw allowing unauthenticated attackers to trigger a heap buffer overflow via crafted HTTP requests. CVSS pending but rated critical. Patched July 15 in nginx 1.30.4 / 1.31.3 and NGINX Plus 37.0.3.1. The overflow lives in nginx's script engine under a specific regex-map configuration; where ASLR is disabled or can be bypassed, F5 warns of potential remote code execution.
SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410) โ Exploited Before Disclosure
A previously undocumented threat actor (UTA0533, tracked by Volexity) exploited two SonicWall SMA 1000 series VPN zero-days as early as June 22, chaining CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) for arbitrary command execution and full device takeover. SonicWall released patches this week.
wp2shell WordPress Core Flaw โ Unauthenticated RCE, PoC Public
Two chained WordPress core vulnerabilities (CVE-2026-63030 โ REST API batch-route confusion; CVE-2026-60137 โ SQL injection) allow anonymous RCE on any 6.9/7.0 site. WordPress shipped 6.9.5 and 7.0.2 with forced auto-updates. A working proof-of-concept is now public on GitHub. Found by Adam Kues (Assetnote / Searchlight Cyber).
OpenSSL "HollowByte" Flaw โ Memory DoS via 11-Byte TLS Request
Defence 1 story
UAC-0145 (Sandworm) Uses ClickFix CAPTCHAs to Infect Ukrainian Devices
Russian GRU-affiliated Sandworm sub-cluster UAC-0145 is using fake CAPTCHA checks on compromised websites to trick Ukrainian targets into executing PowerShell commands that deploy data-stealing malware (GHETTOVIBE, SCOUTCURL). CERT-UA issued an alert detailing the campaign.
Legal / Regulatory 3 stories
EU Orders Google to Open Android to Rival AI Assistants Under DMA
The European Commission adopted two binding specification decisions under the Digital Markets Act requiring Google to give rival AI assistants the same Android system access as Gemini (camera, microphone, screen, wake word, background automation). Google must ship by Android 18, no later than 1 August 2027. A second decision requires Google to share anonymised search query and ranking data with rival search engines and AI chatbots.
Illinois Governor Signs Frontier AI Model Law (SB 315)
Illinois became the third US state (after Connecticut and others) to enact comprehensive safety and transparency requirements for developers of advanced AI systems. The Artificial Intelligence Safety Measures Act imposes obligations on frontier AI model developers covering testing, reporting, and risk mitigation.
CISA Plans to Finalise Cyber Incident Reporting Regulations by September 2026
CISA continues to finalise regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), with a final rule expected in September 2026. The rule will mandate incident reporting for critical infrastructure entities.
Healthcare 1 story
23andMe Reaches $18 Million Settlement with States for 2023 Breach
23andMe reached an $18 million settlement with multiple US states following the massive 2023 data breach that exposed genetic and personal data of millions of customers. The settlement includes security improvement requirements and consumer restitution.
Manufacturing 1 story
Dairy Company Fairlife Suspends US Production After Cyber Incident
Fairlife, a major US dairy company, suspended production at its US facilities following a cyber incident. The nature of the incident (ransomware, disruption, or data breach) has not been publicly detailed. The suspension affects supply chains for Fairlife's retail and food-service customers.
General / Cross-Sector 2 stories
Scattered Spider Hackers Sentenced to 5.5 Years Over ยฃ29M Transport for London Hack
Members of the Scattered Spider cybercrime group were sentenced to 5.5 years in prison for their role in the ยฃ29 million Transport for London (TfL) hack. The sentencing marks a significant law enforcement outcome against the notorious cybercrime gang.
Trump Administration Unveils AI-Supported Clearinghouse for Cyber Vulnerabilities
The White House announced a new AI-supported clearinghouse designed to aggregate and prioritise cybersecurity vulnerabilities from across government and industry sources. The initiative aims to improve vulnerability management and patch prioritisation at scale.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |