Thursday, July 30, 2026
Daily digest
Heavy day for actively exploited vulnerabilities across core enterprise infrastructure — Cisco FMC, Exchange OWA, and VMware all have live exploitation or critical patches — alongside a coordinated OT attack on Minnesota water utilities.
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
CISA added CVE-2026-20316, a static-credential flaw in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities catalog after confirming zero-day exploitation. The flaw (CVSS 5.3) allows an unauthenticated remote attacker to log in using hardcoded credentials and access sensitive data.
Why it matters: If FMC manages any perimeter firewalls in your environment, this is a KEV-listed, actively exploited flaw requiring immediate patching and credential rotation under CMMC's timely remediation expectations.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
A Russian threat actor previously tied to Zimbra exploitation has been exploiting a Microsoft Outlook Web Access vulnerability since July 22, 2026, targeting U.S. and European government, telecom, financial, hospitality, and aerospace organizations. The attack installs a persistent backdoor that survives password changes and device rebuilds.
Why it matters: Persistence that survives credential rotation defeats a standard incident-response containment step; if you run any on-prem/hybrid Exchange OWA alongside GCC High, verify patch status and hunt for browser-based implants immediately.
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom patched multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion, three rated critical. The most severe, CVE-2026-59309 (CVSS 9.8), is an authentication bypass in vCenter exploitable by anyone with network access.
Why it matters: Even on a primarily Nutanix AHV shop, any residual VMware footprint (test labs, legacy VMs, vendor appliances) needs immediate patching given the VM-escape and auth-bypass severity.
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack hit operational technology at more than 30 Minnesota community water systems on July 26-27, prompting a statewide cybersecurity response. Braham's water plant went fully offline and other facilities reported communications failures or affected automated controls.
Why it matters: Suspected Iran-linked CyberAv3ngers involvement underscores continued OT/ICS targeting of critical infrastructure — relevant context for any CMMC-covered contractor with OT/SCADA touchpoints or utility partners.
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Researcher Håkon Måløy disclosed a prompt-injection technique where hidden instructions in a Word document cause Microsoft 365 Copilot to alter content and then propagate the same hidden instructions into newly generated files. The proof-of-concept showed the behavior self-replicating across a second Copilot drafting session, and Microsoft has not yet produced a robust mitigation 144 days after disclosure.
Why it matters: This is a worm-like prompt-injection risk inside Copilot for Word — worth flagging to users in your M365 GCC High tenant and reviewing Copilot data-access policies until Microsoft ships a fix.
Amazon Links Debug and Chalk npm Hijack to North Korea's Sapphire Sleet
Amazon attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet group. The compromise, previously treated as generic crypto theft, involved a maintainer phished via a lookalike npm domain, pushing wallet-draining code into at least 18 packages with over 2 billion combined weekly downloads.
Why it matters: If any Ansible tooling, container builds, or internal apps pull these widely-used npm packages, audit pinned versions and lockfiles from the affected window for supply-chain exposure.
VA Won't Require Existing FedRAMP Certification for Cloud Contracts
A VA memo reveals the department will no longer require cloud vendors to hold existing FedRAMP certification before awarding contracts, with officials framing the move as reducing procurement delays while claiming security standards are maintained.
Why it matters: This signals a broader federal trend toward loosening FedRAMP gatekeeping for procurement speed — watch for whether this pattern extends to DoD/CMMC contexts, potentially affecting vendor risk assumptions in your supply chain.
Navy Using LETHALITY Consortium to Advance Network Consolidation Initiative
The Naval Surface Warfare Center Corona Division is using the LETHALITY Consortium to modernize and consolidate its IT and data architectures as part of a broader network consolidation initiative.
Cisco 'Retires' Its Azure Local Offering Rather Than Catch Up to Microsoft's Hardware Requirements
Cisco is discontinuing its Azure Local hyperconverged offering after Microsoft changed requirements to only allow locked-down hardware with joint software and hardware support for its on-prem hyperconverged cloud platform. Cisco declined to pursue the certification needed to continue supporting the product.
Why it matters: A reminder that Azure Local/hyperconverged competitors are consolidating around vendor-locked hardware — reinforces the case for staying on Nutanix AHV rather than chasing Microsoft's tightening on-prem cloud requirements.
Veeam Adds Support for Six More Hypervisors
Veeam expanded its backup platform to support six additional hypervisors, a move largely aimed at customers migrating away from VMware.
Why it matters: Worth confirming your Nutanix AHV backup coverage is included in the expanded support matrix if Veeam is part of your DR strategy.
Secure Your npm and pip Package Updates in Amazon Linux
AWS published guidance on securing npm and PyPI package installation workflows in Amazon Linux, noting that the first hours after a package is published are the highest-risk window since scanners haven't yet analyzed new releases. The post references recent Node.js and Python supply-chain incidents that were caught and removed within hours of publication.
Why it matters: Directly actionable for any AWS GovCloud workloads using Amazon Linux with npm/pip dependencies — consider applying the recommended delay/verification controls in your Ansible-managed build pipelines.
The Majority of Corporate IT Is Now Off Premises for the First Time
A new survey finds that more enterprise IT workloads now run off-site (cloud/hosted) than in on-premises corporate facilities, marking a first-time crossover point.