Security Newsletter

Daily Security Briefing #321

DjediTech July 20, 2026 3 min read
Daily Security Briefing #321
Table of Contents

July 20, 2026 | Read Online

WebDAV malware delivery labs exposed, AI-assisted phishing toolkit revealed, and SharePoint flaws exploited…


Executive Summary

The past day has seen a surge in cybersecurity threats, with malicious actors adapting to disruptions. Notable incidents include the exposure of a WebDAV malware delivery lab containing over 1,000 artifacts, an AI-assisted phishing toolkit behind a WebDAV campaign, and actively exploited SharePoint flaws allowing hackers to deploy web shells and steal IIS machine keys.



Top Articles

Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign Google Threat Intelligence Group and partners took action against UNC2814, a PRC-nexus cyber espionage group targeting international governments and telecommunications organizations. The campaign, tracked since 2017, disrupted dozens of nations across four continents. Google Cloud Blog

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab An MDR alert led our team to an exposed server hosting payloads and functioning as a fully operational malware delivery lab. The infrastructure contained over 1,000 artifacts, revealing an interesting shift in adversary operations: attackers are adopting generative AI to move. Rapid7

TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details A rapidly evolving malware family dubbed TELEPUZ is gaining traction through a ClickFix–VIDAR infection chain. Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation. GBHackers

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader. The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. The Hacker News

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI, and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. Bleeping Computer

Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys Microsoft SharePoint Server flaws are being actively exploited to deploy web shells, steal IIS machine keys, and maintain long-term access to compromised enterprise environments. CISA has added CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to the list of known vulnerabilities. Cyber Press

An AI SOC Evaluation Guide for Security Leaders Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions. Bleeping Computer

GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain A critical pre-authentication remote code execution (RCE) vulnerability in WordPress has been uncovered not by a human researcher but by an AI system, attributed to OpenAI’s GPT-5.6 Sol Ultra model. Cyber Press

20th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. Check Point


AI Transparency: This newsletter uses AI to curate, rank, and summarize cybersecurity content from leading industry blogs. All articles link directly to original authors. Executive summaries are AI-generated based on article content. I curate the sources and deliver the digest—the original authors deserve the credit for their excellent work.