logo

Critical zero-days in Rails, Ruflo, VMware; Laundry Bear exploits Exchange OWA

ID: 258cfb78-3920-5835-9fc6-97c7570cabd9

STIX ID: report--258cfb78-3920-5835-9fc6-97c7570cabd9

Feed Name: defend.network

Threat Score
90/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: defend.network

...
...

### Executive Summary This briefing reports multiple high-severity vulnerabilities and active campaigns: a Ruflo MCP RCE (CVE-2026-59726) and Cisco FMC static-credential exploitation (CVE-2026-20316) are highlighted alongside reported Ruby on Rails and VMware critical flaws; Russian state-aligned group Laundry Bear is actively exploiting an Exchange OWA zero-day with the OWAReaper backdoor for persistent mailbox access; and a coordinated cyberattack disrupted operational technology at 30+ Minnesota community water systems—collectively prompting urgent patching, threat hunting, OT incident response, and vendor coordination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.