Chuyển đến nội dung
Cybersecurity

Bản tin bảo mật ngày 25/07/2026: các điểm nóng cần chú ý

cybersecurity briefing 2026 07 25

Cập nhật nhanh các tin an ninh mạng đáng chú ý trong ngày 25/07/2026, được biên tập tự động cho độc giả gocdulieu.com từ các nguồn bảo mật công khai. Bài viết tập trung vào rủi ro có thể ảnh hưởng tới quản trị viên hệ thống, đội vận hành bảo mật và doanh nghiệp.

Điểm nóng bảo mật

  • Google gives developers an AI bug hunter that also writes patches — Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to attackers Nguồn: Help Net Security (24/07 15:53).
  • Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes — A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the passwo Nguồn: The Hacker News (24/07 01:36).
  • Default Azure Automation Setting Enables Cross-Tenant Identity Takeover — Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, and cloud workloads. Nguồn: Dark Reading (24/07 19:48).
  • Hermes AI agent used to automate attack on Thai Finance Ministry — A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. […] Nguồn: BleepingComputer (25/07 02:09).
  • NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source cod Nguồn: The Hacker News (24/07 14:41).
  • Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 ch Nguồn: The Hacker News (24/07 13:58).

Ưu tiên xử lý trong 24–48 giờ

  1. Kiểm kê các dịch vụ public-facing: VPN, gateway, IAM/NAC, remote support, dashboard quản trị và hệ thống có quyền cao.
  2. Đối chiếu phiên bản với advisory chính thức; ưu tiên vá lỗ hổng đang bị khai thác, có PoC công khai hoặc ảnh hưởng thiết bị biên.
  3. Rà soát log đăng nhập, thay đổi cấu hình, session/token bất thường và dấu hiệu truy cập từ hạ tầng lạ.
  4. Với AI agent/plugin/extension, áp dụng quyền tối thiểu, bật logging cho tool-call/API call và tách dữ liệu nhạy cảm khỏi môi trường thử nghiệm.

CISA KEV / lỗ hổng cần theo dõi

  • CISA KEV chưa truy cập được từ môi trường tự động (HTTPError: HTTP Error 403: Forbidden); cần đối chiếu thủ công nếu đang xử lý hệ thống trọng yếu.

Nguồn tham khảo

Lưu ý: Bản tin được biên tập theo hướng thực hành; trước khi áp dụng thay đổi trên hệ thống production, anh/chị nên đối chiếu với advisory chính thức của nhà cung cấp và quy trình change management nội bộ.

Tham gia thảo luận

Your email address will not be published. Required fields are marked *