CyberSecurity Events for this week: July 31, 2026

Jul 31, 2026Incognito CyberSecurity

By Nemuel Cruz, Incognito CyberSecurity™

Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to small businesses across Southern Arizona. Here is the cybersecurity news that mattered this week — July 27 through July 31, 2026 — translated into plain English, with the specific action a business owner should take on each one.

1. CISA flags two edge-device flaws being actively exploited

On July 27, CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming attackers are using them in the wild. One is a maximum-severity (CVSS 10) command-injection flaw in Arista’s VeloCloud Orchestrator (CVE-2026-16812) that lets an unauthenticated attacker take over networking infrastructure. The other is a Fortinet FortiOS flaw (CVE-2025-68686) that lets attackers bypass a patch meant to stop them from leaving hidden backdoors on a compromised firewall. Federal agencies were ordered to fix these by July 30 and August 10.

What to do: If your firewall or SD-WAN gear is Fortinet or VeloCloud, patch it this week — internet-facing devices are the first thing attackers probe. If you don’t know exactly what sits on the edge of your network, that is the real problem. A managed network solutions provider inventories every internet-facing device and keeps its firmware current so you are not the easy target.

2. Cyberattack forces 30-plus Minnesota water systems onto manual controls

A coordinated attack disrupted the operational technology at more than 30 Minnesota community water systems on July 26 and 27, forcing crews in towns such as Braham, South St. Paul, and Plymouth to run their plants by hand while the state activated its incident-response plan alongside CISA, the EPA, and the FBI. Small municipal utilities rarely have dedicated security staff — which is exactly why they were hit.

What to do: The lesson here is not about water. It is that attackers target the operations that cannot afford downtime and do not have a security team watching. Separate the systems that run your business from the ones staff use for email and web browsing, and keep tested, offline secure data backups so a single break-in cannot take everything down at once.

3. Public exploit lands for a critical vBulletin forum flaw

On July 27, researchers published working exploit code for CVE-2026-61511, an unauthenticated remote-code-execution bug in the vBulletin forum platform. The flaw lets anyone send a crafted web request that reaches PHP’s eval() function and runs code on an unpatched server — no login required. vBulletin shipped fixes in late June (version 6.2.2 arrived July 1), but many forums are still running vulnerable 5.x and 6.x builds.

What to do: If you run any web application — a forum, a CMS, a customer portal — the moment a public exploit drops, your patch window shrinks from weeks to hours. Confirm your web software is on the latest version today. If you are not sure what is running on your site or whether it has already been probed, a network penetration test will find the holes before an attacker does.

4. Amazon ties a major npm supply-chain hijack to North Korea

On July 30, Amazon’s threat researchers linked the hijack of the widely used npm packages “debug” and “chalk” to North Korean operators. A package maintainer was phished through a lookalike npm domain, and attackers slipped a wallet-draining script into at least 18 packages that together see more than 2 billion downloads a week. It is a sharp reminder that the code your software depends on can be poisoned upstream.

What to do: You may not write software, but the apps and tools you buy do — and a compromised update can walk straight through the front door. Keep endpoint protection on every workstation so a malicious payload is caught even when it arrives inside trusted software, and train staff to spot the phishing emails that kick these attacks off.

5. A new “ghost” phishing wave is slipping past email security

Security teams reported a surge this week in phishing that bypasses traditional email filters, driven heavily by abuse of Microsoft’s OAuth “device-code” login flow and adversary-in-the-middle kits built to steal Microsoft 365 credentials. Researchers tracked more than 7,000 phishing uploads in a single week. These attacks do not rely on a suspicious attachment — they trick users into approving a genuine login prompt, which sails right past spam filters.

What to do: Filters alone will not stop this. Turn on phishing-resistant multi-factor authentication for Microsoft 365, review which apps are allowed to connect to your tenant, and layer strong spam and virus filtering in front of your inbox. For any small business running on Microsoft 365, this is the highest-value control you can add this month.

6. 7,600 fake GitHub repositories are pushing malware — and fooling AI tools

A campaign dubbed “FakeGit” has been using roughly 7,600 malicious GitHub repositories to spread a malware loader called SmartLoader, which then pulls down information-stealers. More than 800 of the fake repos pose as AI tools or plug-ins, and they are crafted to trick both developers and AI coding assistants into recommending and installing them. Some have logged millions of downloads.

What to do: Anyone on your team downloading tools, scripts, or “AI helpers” off the internet is a target. Set a rule that software gets installed from vetted sources only, and back it with small business cybersecurity solutions that block untrusted programs before they run. A convenience download is exactly how a stealer ends up on the machine you use for payroll and banking.

The bottom line

The through-line this week: attackers keep hitting edge devices, unpatched web apps, and Microsoft 365 logins — the exact spots small businesses tend to leave unwatched. Patch fast, back up offline, and lock down your identities. Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona. Want a second set of eyes on your defenses? Contact Incognito Cyber Security and we will help you close the gaps before they become headlines.

Related

Latest News