Isometric network nodes highlighting global cybersecurity flaws and breaches.

Daily Cybersecurity News - July 8, 2026

CISA Orders Feds to Patch Langflow Flaw

CISA told federal agencies to patch a Langflow auth bypass by Friday. Attackers are already inside.

The flaw lets authenticated attackers execute flows belonging to other Langflow users by supplying a victim’s flow ID. CVSS 9.9, actively exploited.

Affects Langflow versions before 1.9.1. Federal networks, research labs, and anyone running the open-source framework need to move.

CISA added the bug to its Known Exploited Vulnerabilities list hours before the directive.

Ubiquiti Ships Max Severity UniFi OS Fixes

Ubiquiti just patched seven critical flaws in UniFi OS. One hits maximum severity and allows unauthenticated command injection.

The top issue, CVE-2026-50746, is a maximum-severity flaw in the UniFi Connect Application that can allow an attacker with network access to execute command injection on the host device.

It affects UniFi Connect Application 3.4.16 and earlier. Ubiquiti recommends updating to version 3.4.20 or later.

Public PoC appeared within 24 hours of the advisory.

KDDI Breach Exposes 12 Million Emails And Passwords

KDDI confirmed a breach at an email platform shared by five Japanese ISPs, exposing customer credentials.

Attackers accessed 12,233,087 email addresses and passwords associated with 7,616,173 accounts. The affected platform supported multiple providers beyond KDDI.

KDDI said some passwords were hashed or encrypted, but did not disclose how many were protected or what encryption was used. The platform's multi-tenant design spread exposure across several ISPs at once.

The same email platform also served customers of four other providers, widening the blast radius.

Accenture Confirms Breach After Hacker Offers Stolen Data

A hacker listed 35 GB of Accenture data for sale on a forum.

Accenture confirmed a security breach, while the attacker claims the stolen 35 GB includes source code, keys, tokens, and configuration files. Accenture has not confirmed the amount or type of stolen data.

The listing appeared before any official disclosure, forcing Accenture to respond publicly.

The data was offered by a single actor rather than a known group like ShinyHunters.

Entra Passkey Enrollment Vishing Targets Microsoft 365 Users

A threat actor is hitting Microsoft 365 users with voice phishing calls that push fake security alerts.

Attackers impersonate IT staff and direct victims to enroll a new Entra passkey on a malicious site. The campaign spans multiple sectors and geographies.

The angle here is the shift to voice-based initial access for passkey enrollment, which bypasses email filters entirely. It reuses common vishing scripts but targets a high-value authentication vector.

Active since April 2026, targeting organizations across multiple sectors.

Chinese Hackers Build Longleash To Grow ORB Network

UAT-7810 is expanding an Operational Relay Box network by compromising internet-facing routers.

They dropped LONGLEASH malware on unpatched Ruckus devices to turn them into relays for later operations.

The move shows China-aligned crews still favor routers as cheap, hard-to-monitor infrastructure instead of new zero-days.

Activity lines up with the same group's prior ORB builds documented since 2024.

AI Coding Agents Trigger Endpoint Rules

AI coding agents are firing endpoint detections written to spot attackers.

Sophos reviewed one week of its telemetry and found tools like Claude Code Cursor and OpenAI Codex generating the same behavioral signals as intruders.

The agents are benign. They simply perform rapid file writes, process spawns, and network calls that legacy behavioral rules treat as suspicious.

The data covered a single week of Sophos customer endpoints.