Daily cybersecurity briefing

Top 10 Cybersecurity Stories for July 25, 2026

Self-managed GitLab systems missing the June security update and internet-exposed PTC Windchill or FlexPLM deployments require immediate attention: public GitLab exploit code is available, while Cl0p affiliates are using an unauthenticated RCE chain for data theft and extortion. Security teams should also account for the shift toward real-time phishing session hijacking and assess exposure to the reported Rockwell Arena code-execution flaws. Prompt patching, credential monitoring, and review of third-party incidents remain the practical priorities.

Compiled by the Slugnet Editorial System. Published Jul 25, 2026, 8:01 AM EDT Updated Jul 26, 2026, 10:11 AM EDT

This legacy edition is awaiting expanded Slugnet analysis and is not yet indexed.

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    What happened

    Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a pro

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    What happened

    For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recen

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    What happened

    Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication infor

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    What happened

    The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the ce

    This legacy edition predates Slugnet’s expanded analytical assessment.

    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
  6. 06
  7. 07
  8. 08
  9. 09
  10. 10