Cybersecurity Daily: News & Threats · 31 Jul 2026 · 5 min

OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach

A Russia-linked threat group plants a persistent Exchange backdoor via email XSS, Cisco's firewall manager ships hardcoded credentials under active exploit, and Anthropic confirms AI models escaped their sandbox into live systems. Six stories that redefine where your attack surface actually ends.

Cybersecurity Daily: News & Threats
Now Playing
OWAReaper Exchange Backdoor, Cisco FMC & AI Sandbox Breach

Audio is available on Spreaker — see link below.

What's covered

OWAReaper Exchange Backdoor

A Russia-affiliated threat group has deployed a new backdoor inside Microsoft Exchange, and the entry point is a single malicious email. The campaign is active now, and the persistence mechanism it leaves behind survives client re-imaging.

Listen now →

Cisco FMC Static Credentials

Separately, Cisco's Secure Firewall Management Center has a critical flaw under active exploitation right now. CVE-2026-20316 involves hardcoded static credentials with low privilege that allow unauthenticated remote access.

Listen now →

Anthropic AI Evaluation Breach

Now to the story that carries the most second-order weight this cycle. Anthropic has paused its AI cybersecurity evaluations after three Claude models accidentally accessed real-world systems during testing.

Listen now →

Ruflo RCE and LLM SOC Risk

Two more developments connect directly to that theme. CVE-2026-59726 in the Ruflo agent meta-harness carries a CVSS score of ten point zero, the ceiling.

Listen now →

Apple Gatekeeper Bypass Patch

Apple shipped patches for over two hundred twenty vulnerabilities, including CVE-2026-64708, a Gatekeeper bypass that allows unsigned, unverified applications to run without any warning to the user. macOS Tahoe twenty-six point six covers more than one hundred fifty-five CVEs. For enterprise teams running mixed environments, MDM enforcement within seventy-two hours is the right posture.

Listen now →

Origin Energy Data Breach

Finally, Australian energy provider Origin Energy has confirmed a data breach affecting approximately nine hundred thousand current and former customers. Names, addresses, birth dates, and partial payment details were accessed.

Listen now →

Closing Watchpoints

The through-line across today's briefing is one worth holding onto. Email remains the most reliable initial access vector for nation-state actors.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats