GÓC DỮ LIỆU // TECH LIBRARYNỘI DUNG CÔNG NGHỆ ĐƯỢC CHỌN LỌC
CYBERSECURITY DESKNội dung công nghệ được chọn lọc, trình bày rõ ràng và ưu tiên giá trị thực hành.
TRANG CHỦ  /  CYBERSECURITY  /  BÀI VIẾT
CYBERSECURITY // TECH LIBRARY

Bản tin bảo mật ngày 21/07/2026: các điểm nóng cần chú ý

Bản tin bảo mật ngày 21/07/2026: các lỗ hổng, chiến dịch tấn công và khuyến nghị ưu tiên xử lý trong 24–48 giờ.

cybersecurity briefing 2026 07 21

Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 21/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.

Điểm nóng bảo mật

  • SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch — The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek . Nguồn: SecurityWeek (20/07 21:11).
  • ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More — A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prom Nguồn: The Hacker News (20/07 20:32).
  • SonicWall SMA1000 flaws exploited as zero-days to push custom malware — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […] Nguồn: BleepingComputer (21/07 05:23).
  • ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) — Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that l Nguồn: Help Net Security (20/07 21:32).
  • Critical ServiceNow code execution flaw now exploited in attacks — Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […] Nguồn: BleepingComputer (20/07 16:29).
  • Meet Dusseldorf, Microsoft’s open-source out-of-band security platform — Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project f Nguồn: Help Net Security (20/07 13:00).

Ưu tiên xử lý trong 24–48 giờ

  1. Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
  2. Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
  3. Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
  4. Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.

CISA KEV / lỗ hổng cần theo dõi

  • CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.

Nguồn tham khảo

Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.