Security Newsletter

Daily Security Briefing #322

DjediTech July 21, 2026 3 min read
Daily Security Briefing #322
Table of Contents

July 21, 2026 | Read Online

GRIDTIDE disrupted, AI surveillance cameras deployed at MIT, and critical SharePoint RCE flaw exploited…


Executive Summary

Cybersecurity threats continue to evolve with malicious actors adapting to disruptions. The recent GRIDTIDE campaign disruption highlights collaborative efforts between industry partners. Meanwhile, the deployment of AI surveillance cameras at MIT raises concerns about data privacy and security. Additionally, a critical vulnerability in Microsoft SharePoint has been exploited by hackers.



Top Articles

MIT to Become Hotbed of AI Video Surveillance The Massachusetts Institute of Technology (MIT) is installing over 500 AI-powered surveillance cameras across its campus, sparking concerns about data privacy and security. The cameras are capable of advanced facial recognition and object detection. Schneier

Inline Email Security and Microsoft 365: A Practical View Microsoft’s guidance on inbound and outbound mail routing for third-party email security has prompted a question from customers: how should organizations evaluate inline email security for Microsoft 365? The answer depends less on whether a solution is inline and more on how that inline architecture is implemented. Checkpoint Blog

Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers Attackers are leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated through malicious websites, file-sharing platforms, and spoofed download portals. GBHackers

Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT The Cruciferra crypter-as-a-service is being abused by hackers to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy commodity malware in email-driven campaigns targeting multiple sectors worldwide. GBHackers

When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at Risk Attackers used more than 20 hijacked Brazilian government websites to support a campaign targeting banking organizations. By hiding behind trusted public-sector infrastructure, PhantomEnigma made malicious activity harder to detect. CyberPress

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has addressed a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, undermining the feature’s privacy guarantees. The Hacker News

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers The tool combines payload encryption with advanced Windows evasion methods, helping attackers bypass endpoint defenses and complicate incident response. CyberPress

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code A hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine. The Hacker News

Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. Bleeping Computer

Critical SharePoint RCE Flaw Exploited to Steal Machine Keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. Bleeping Computer

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity. Security Week


AI Transparency: This newsletter uses AI to curate, rank, and summarize cybersecurity content from leading industry blogs. All articles link directly to original authors. Executive summaries are AI-generated based on article content. I curate the sources and deliver the digest—the original authors deserve the credit for their excellent work.