Cyber Briefing: 2026.07.30
Attackers are combining sophisticated zero-interaction web exploits and deceptive social engineering to breach critical systems, driving the industry toward AI-automated threat hunting.
Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
State-backed actors and malware operators are targeting both enterprise communications and end-user platforms to gain persistent access and exfiltrate sensitive data. Russian threat group TA488 actively exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Exchange Outlook Web Access to deploy a persistent browser backdoor called OWAReaper simply when targets viewed malicious emails. Concurrently, macOS users face targeted credential theft through MacSync, a six-stage malware family distributed via fake Google ads and spoofed support pages for Claude AI that deceives victims into running malicious Terminal commands to compromise browser data, crypto wallets, and SSH keys.
In response to rising operational threats, demonstrated by a coordinated cyberattack impacting over 30 Minnesota water utilities’ operational technology systems, industry vendors and authorities are focusing on automated defenses and strict isolation. Security teams are turning to new AI-driven tools, such as PortSwigger’s agentic AI penetration testing assistant Burp AT and Dropzone AI’s automated AI Threat Hunter, to discover hidden security gaps proactively. At the same time, new critical infrastructure guidance (CI Fortify Guide) urges operators to implement a structured, six-step process to segment and isolate operational technology networks to contain incidents and preserve vital services.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
Russian hackers exploit Exchange XSS flaw for mailbox takeov
A Russia-aligned threat group designated TA488 exploited CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange’s Outlook Web Access, to install a browser-based backdoor called OWAReaper when recipients simply viewed malicious emails. The campaign, which began in July 2026 and targeted government and private sector organizations in the US and Europe, allowed attackers to establish persistent mailbox access that survives password resets and endpoint reimaging. Organizations using affected Exchange Server versions (2016, 2019, and Subscription Edition) should apply Microsoft’s July 2026 security update, audit mailbox permissions and OAuth tokens, and implement cross-layer monitoring that correlates OWA activity with permission changes. Read More
MacSync: Six-Stage macOS Stealer via Fake Claude
Security researchers at Huntress have identified MacSync, a previously unknown macOS malware family distributed through malicious Google ads impersonating Claude AI installation guides. The attack begins when victims click a sponsored search result leading to a fake support page hosted on Anthropic’s legitimate claude.ai domain, which instructs users to paste a malicious command into Terminal. The six-stage infection chain steals browser credentials, cryptocurrency wallet data, SSH keys, and Telegram sessions, while also deploying a remote access trojan and replacing legitimate hardware wallet applications with modified versions designed to capture recovery phrases. Read More
🚨INCIDENTS & REAL-WORLD IMPACT
Coordinated cyberattack hits 30+ Minnesota water utilities
More than 30 community water utilities in Minnesota experienced a coordinated cyberattack targeting their operational technology systems on July 26-27, 2024. Minnesota IT Services (MNIT) confirmed the incident and activated its cybersecurity incident response capabilities immediately upon discovery. The agency is working with partners to contain the threat, though specific details about the attackers, methods used, or extent of operational disruption have not been disclosed. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
PortSwigger launches Burp AT agentic AI tool
PortSwigger has released a public beta of Burp AT, an agentic AI tool integrated into Burp Suite for penetration testing. The tool allows security testers to delegate investigative tasks to AI agents that operate within defined scope and permission boundaries, while human testers retain control over validation and judgment. Burp AT uses Burp Suite’s existing tools and project context to perform automated security testing tasks under tester supervision. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
CI Fortify Guide for Critical Infrastructure
A new CI Fortify Guide from cybersecurity authorities advises critical infrastructure operators to isolate vital operational technology (OT) systems from other networks to contain cyber incidents and maintain essential services during attacks. The guidance provides a six-step process for network isolation, starting with identifying minimum systems needed for critical services and progressing through mapping connections, building separation points, and testing isolation plans. Operators are urged to implement graduated isolation approaches that can escalate to complete physical separation of vital systems when threat levels increase, while maintaining secure offline copies of isolation procedures and monitoring for unauthorized reconnections. Read More
💻 CAREER ENABLEMENT
Dropzone AI launches AI Threat Hunter tool
Dropzone AI has released AI Threat Hunter, an automated threat hunting tool designed to help security operations centers identify hidden threats and coverage gaps that standard alert systems miss. The tool runs structured hunt packs across enterprise environments to proactively search for emerging risks beyond what predefined detection rules catch. Security teams can use this agent to make threat hunting a regular operational activity rather than an occasional manual exercise. Read More
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium








