Attackers have exploited a critical authentication bypass vulnerability, identified as CVE-2026-18577, in N-able N-central, a remote monitoring and management solution. This flaw allows unauthorized access to managed endpoints.
Separately, a pre-authentication remote code execution vulnerability was discovered in Bonita BPM, a workflow automation platform used in sectors like banking and government. Researchers at Novee found that a single unauthenticated web request could allow attackers to access an internal Bonita API and execute code on the server. This finding was presented at Black Hat USA 2026.
Another significant vulnerability, CVE-2026-66066, affects Ruby on Rails, a popular framework for web applications. This critical flaw, dubbed KindaRails2Shell, could enable attackers to read sensitive files from a server and, in some instances, achieve full control over it.
In other incidents, the Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) confirmed that vulnerabilities in their Microsoft SharePoint servers led to the compromise of approximately 200 login credentials.
Forescout’s Vedere Labs uncovered 15 vulnerabilities within TP-Link’s Omada networking platform. One attack chain leveraged the sequential nature of Omada router serial numbers, which are printed on devices and packaging. By guessing a serial number, attackers could query the Omada cloud to reveal a device’s MAC address and model, such as identifying ER605 routers from serials starting with 22460J500 or ER7206 models from 224608100. These vulnerabilities could allow attackers to hijack routers and intercept camera traffic.
Kaspersky ICS CERT reported approximately forty attacks on industrial organizations in the second quarter of 2026. One notable incident involved an Israeli food producer where intruders manipulated a refrigeration system by switching gas cooler and receiver valves to manual and pinning them open. This action caused liquid CO2 to flood and destroy compressors, necessitating a week-long rebuild and system recalibration with replacement units.
A phishing campaign impersonating Bank of America is actively targeting Windows users. The campaign aims to trick users into installing ScreenConnect remote access software and then employs tactics to make its uninstallation difficult.
In other security news, Palo Alto Networks’ Unit 42 developed an automated system called NOVA, which analyzed the source code of 3,915 open-source projects over two months. NOVA identified 14,090 vulnerabilities, each confirmed through its validation pipeline, and its findings were cross-referenced with public records.
Researchers at 1Password investigated the effectiveness of AI-generated vulnerability patches. They found that while frontier models often produce convincing code that may pass tests, only about one in four patches for six newly disclosed CVEs actually fixed the vulnerability. The remaining patches either addressed only part of the issue or introduced new flaws.
Cloudflare has open-sourced Cloudflare OS, an AI agent platform previously used internally since May. This platform tracks every resource an agent accesses and incorporates that context into its outputs. When an output is accessed, Cloudflare OS verifies that the user has permission to view the underlying data; for example, a dashboard built from a sensitive database table would remain hidden from users without access to that table.
OpenAI has updated its ChatGPT models, pushing GPT-5.6 Luna to free-tier users and GPT-5.6 Sol to Plus and Pro subscribers. The company has also removed text chat limits for free users and introduced new safeguards for teenagers.
Microsoft’s July 2026 Patch Tuesday was described as record-setting, with the highest volume of security patches ever released across nearly every product in its portfolio, addressing well over 600 CVEs. This has prompted discussions about the challenges of managing such a high volume of patches.






